Debugging symbols left in Siemens Reyrolle 7SR5 relay firmware (versions before V2.70)
AI analysis
Siemens has reported that Reyrolle 7SR5 protection relay firmware versions prior to V2.70 ship with binaries from which debugging symbols were not stripped (CWE-215). An unauthenticated attacker does not need access to the device itself; the flaw is triggered by downloading the publicly available firmware update files and analyzing them offline. What the attacker gains is not direct control of the relay but a significantly easier reverse-engineering path, which lowers the effort required to find exploitable memory-corruption, authentication, or protocol weaknesses in the same firmware. Affected devices are Reyrolle 7SR5 numerical protection relays, typically deployed in medium-voltage distribution substations at utilities and industrial sites, running any version older than V2.70. There is no known public proof of concept, the CVE is not in the CISA KEV catalog, and EPSS estimates only about a 0.2% chance of exploitation in the next 30 days, consistent with an informational/hardening weakness rather than a directly weaponizable bug.
What to do: Update Reyrolle 7SR5 relays to firmware V2.70 or later once a suitable maintenance window is available, since fixed builds strip the debugging symbols. In the interim, treat publicly hosted firmware images as sensitive: restrict where update files are stored and shared, and ensure relay engineering ports and firmware-update access are limited to segmented, authenticated OT networks rather than routable paths. Also verify that no analyst tooling or older firmware copies have been left on internet-accessible file shares, and monitor Siemens advisories for follow-on vulnerabilities that this easier reverse engineering could uncover.
Affected
| Siemens (Siemens Energy, Reyrolle product line) Reyrolle 7SR5 | All versions < V2.70 |
Estimated exposure
nichelikely low thousands of deployed relays at utility and industrial sites, with minimal direct internet exposure (clearly an estimate) — Reyrolle 7SR5 relays are specialized distribution-protection hardware sold into utility substations rather than a mass-market product, and such OT devices are generally deployed on private engineering networks with little public scan data…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.