ZeroHour

CVE-2026-62653

niche

Physical-access memory corruption in Siemens Reyrolle 7SR5 protection relays

CVSS 4.0
7.0 high
EPSS
<1%p8
Published
()
Modified
AI analysis

Siemens Reyrolle 7SR5 protection relays running firmware older than V2.70 contain a memory-corruption flaw (CWE-787) in the input handling of a proprietary communication protocol that is exposed when the device is placed into a special firmware-update mode. An unauthenticated attacker with physical access can feed malformed protocol input during this mode, triggering the corruption, which crashes the device and could potentially allow arbitrary code execution on the relay. Because the attack vector is physical, the flaw cannot be triggered remotely or over the internet, and the relay's protective functions are not impacted beyond the device itself (no subsequent system impact in the CVSS score). All Reyrolle 7SR5 deployments on firmware below V2.70 are affected. There is currently no known public proof-of-concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.2% probability of exploitation within 30 days.

What to do: Upgrade Reyrolle 7SR5 relays to firmware V2.70 or later, prioritizing units where untrusted personnel may have physical access. Until patched, restrict physical access to relays and avoid placing devices into the special firmware-update mode except during controlled maintenance. Check asset-management records or relay configuration files to inventory which 7SR5 units you operate and their firmware versions.

Affected
Siemens Reyrolle 7SR5 protection relayAll versions < V2.70
Estimated exposure
nichelikely on the order of tens of thousands of deployed relay units worldwide (estimate; no public install counts) — Reyrolle 7SR5 relays are specialized feeder-protection devices installed per-substation in utility and industrial power networks, are not typically internet-exposed, and the flaw additionally requires physical access during a special…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is placed into a special firmware-update mode is not properly validated, resulting in a memory corruption condition. This could allow an unauthenticated attacker with physical access to the device to cause a crash and potentially execute arbitrary code on the device.

Weakness
CWE-787
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Siemens Reyrolle 7SR5

CISA advisory covers 14 vulnerabilities, CVSS 9.8, in Siemens Reyrolle 7SR5 energy-sector protection relays before V2.70.

CISA advisory ICSA-26-258-05 covers 14 vulnerabilities in Siemens Reyrolle 7SR5 protection relays before V2.70, used in the energy sector worldwide, with aggregate CVSS v3 of 9.8. Flaws include Cesanta Mongoose web server issues (CVE-2024-42384 through CVE-2024-42392) and new bugs such as web-interface session-ID exposure enabling authentication bypass (CVE-2026-62645, CVSS 9.8), predictable session tokens (CVE-2026-62646, CVE-2026-62647), and pre-auth out-of-bounds writes (CVE-2026-62648). Siemens has released V2.70 and recommends updating to the latest version.