VORANT. Threat Intelligence Sign in Get the full feed

Siemens Reyrolle 7SR5 relays get patched for 14 flaws

routine vulnerability energy

Siemens fixed 14 vulnerabilities in Reyrolle 7SR5 protection relays before V2.70, including auth bypass, DoS, and code-execution issues; update to V2.70+.

Siemens has disclosed 14 vulnerabilities affecting Reyrolle 7SR5 protective relay devices running firmware prior to V2.70, used in energy sector critical infrastructure worldwide. Five of the flaws (CVE-2024-42384/42385/42386/42391/42392) stem from the embedded Cesanta Mongoose web server and allow remote attackers to crash the device via malformed TLS packets or trigger memory corruption/infinite loops via malformed PEM certificates or input strings.

The remaining nine CVEs (CVE-2026-62645 through 62654, excluding 62651) are Siemens-specific weaknesses in the device's web management interface and firmware. These include predictable/low-entropy session identifiers and insufficient RNG initialization that could let an unauthenticated remote attacker derive valid sessions and impersonate an authenticated user (CVE-2026-62645/62646/62647); an out-of-bounds write from unvalidated URL length in pre-auth HTTP messages causing remote DoS/reboot (CVE-2026-62648); resource exhaustion under high concurrent HTTP load causing device crash (CVE-2026-62649); and a server-side RBAC bypass allowing a low-privileged authenticated user to escalate to admin (CVE-2026-62650). Physical-access issues include unremoved debug symbols easing firmware reverse engineering (CVE-2026-62652), memory corruption in a proprietary firmware-update protocol enabling potential code execution (CVE-2026-62653), and a maintenance mode activated via a physical key sequence that downloads and executes unsigned code from a network server without integrity checks (CVE-2026-62654).

Siemens has released V2.70 to remediate all issues and recommends applying it via documented update procedures. No exploitation in the wild has been reported; this is a coordinated vendor disclosure via Siemens ProductCERT (SSA-142885) republished by CISA. Standard ICS hardening is advised: network segmentation, isolating control system networks from business/internet-facing networks, and secure remote access via VPN where required.

Mentioned in this report

Vulnerabilities CVE-2024-42384CVE-2024-42385CVE-2024-42386CVE-2024-42391CVE-2024-42392CVE-2026-62645CVE-2026-62646CVE-2026-62647CVE-2026-62648CVE-2026-62649CVE-2026-62650CVE-2026-62652CVE-2026-62653CVE-2026-62654

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-05

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free