Siemens Reyrolle 7SR5 relays get patched for 14 flaws
Siemens fixed 14 vulnerabilities in Reyrolle 7SR5 protection relays before V2.70, including auth bypass, DoS, and code-execution issues; update to V2.70+.
Siemens has disclosed 14 vulnerabilities affecting Reyrolle 7SR5 protective relay devices running firmware prior to V2.70, used in energy sector critical infrastructure worldwide. Five of the flaws (CVE-2024-42384/42385/42386/42391/42392) stem from the embedded Cesanta Mongoose web server and allow remote attackers to crash the device via malformed TLS packets or trigger memory corruption/infinite loops via malformed PEM certificates or input strings.
The remaining nine CVEs (CVE-2026-62645 through 62654, excluding 62651) are Siemens-specific weaknesses in the device's web management interface and firmware. These include predictable/low-entropy session identifiers and insufficient RNG initialization that could let an unauthenticated remote attacker derive valid sessions and impersonate an authenticated user (CVE-2026-62645/62646/62647); an out-of-bounds write from unvalidated URL length in pre-auth HTTP messages causing remote DoS/reboot (CVE-2026-62648); resource exhaustion under high concurrent HTTP load causing device crash (CVE-2026-62649); and a server-side RBAC bypass allowing a low-privileged authenticated user to escalate to admin (CVE-2026-62650). Physical-access issues include unremoved debug symbols easing firmware reverse engineering (CVE-2026-62652), memory corruption in a proprietary firmware-update protocol enabling potential code execution (CVE-2026-62653), and a maintenance mode activated via a physical key sequence that downloads and executes unsigned code from a network server without integrity checks (CVE-2026-62654).
Siemens has released V2.70 to remediate all issues and recommends applying it via documented update procedures. No exploitation in the wild has been reported; this is a coordinated vendor disclosure via Siemens ProductCERT (SSA-142885) republished by CISA. Standard ICS hardening is advised: network segmentation, isolating control system networks from business/internet-facing networks, and secure remote access via VPN where required.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-05
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free