Siemens Reyrolle 7SR5
Siemens Reyrolle 7SR5 devices affected by multiple critical vulnerabilities.
Summary
Siemens has released a security advisory for its Reyrolle 7SR5 devices, detailing multiple vulnerabilities affecting versions prior to V2.70. These vulnerabilities, including integer overflows, out-of-bounds writes, and authentication bypass, could allow attackers to cause denial-of-service conditions, gain unauthorized access, or potentially execute arbitrary code. Siemens recommends updating to the latest version to mitigate these risks.
Full text
ICS Advisory Siemens Reyrolle 7SR5 Release DateSeptember 15, 2026 Alert CodeICSA-26-258-05 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7SR5 are affected: Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CVE-2026-62654) CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens Reyrolle 7SR5 Integer Overflow or Wraparound, Improper Neutralization of Delimiters, Use of Out-of-range Pointer Offset, Missing Authentication for Critical Function, Insufficient Entropy, Improper Input Validation, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Authentication Bypass Using an Alternate Path or Channel, Insertion of Sensitive Information Into Debugging Code, Download of Code Without Integrity Check Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2024-42384 Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-190 Integer Overflow or Wraparound Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2024-42385 Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-140 Improper Neutralization of Delimiters Metrics CVSS Version Base Score Base Severity Vector String 3.1 4 MEDIUM CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H CVE-2024-42386 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-823 Use of Out-of-range Pointer Offset Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.2 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H CVE-2024-42391 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-823 Use of Out-of-range Pointer Offset Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVE-2024-42392 Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-140 Improper Neutralization of Delimiters Metrics CVSS Version Base Score Base Severity Vector String 3.1 4 MEDIUM CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H CVE-2026-62645 Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2026-62646 A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-331 Insufficient Entropy Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.4 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2026-62647 A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-20 Improper Input Validation Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.4 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2026-62648 The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:Reyrolle 7SR5 < V2.70 Product Status:known_affected Remediations Vendor fixUpdate to V2.70 or later versionhttps://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-62649 The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire device to crash and reboot, resulting in a denial-of-service condition. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor:Sieme
Indicators of Compromise
- cve — CVE-2024-42384
- cve — CVE-2024-42385
- cve — CVE-2024-42386
- cve — CVE-2024-42391
- cve — CVE-2024-42392
- cve — CVE-2026-62645
- cve — CVE-2026-62646
- cve — CVE-2026-62647
- cve — CVE-2026-62648
- cve — CVE-2026-62649
- cve — CVE-2026-62650
- cve — CVE-2026-62652
- cve — CVE-2026-62653
- cve — CVE-2026-62654