{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asiemensreyrolle_7sr5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:siemens:reyrolle_7sr5:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-62650"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Reyrolle 7SR5 (\u003c V2.70)"],"_cs_severities":["high"],"_cs_tags":["ics","energy","firmware-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Siemens"],"content_html":"\u003cp\u003eSiemens Reyrolle 7SR5 protection devices with firmware versions earlier than V2.70 contain multiple high-severity vulnerabilities derived from the integrated Cesanta Mongoose Web Server (v7.14). The identified security flaws include integer overflows, out-of-bounds pointer usage, improper neutralization of delimiters, and authentication bypass via predictable session identifiers. These issues affect critical energy infrastructure devices deployed globally.\u003c/p\u003e\n\u003cp\u003eAn attacker with network access could exploit these vulnerabilities to cause service disruptions via segmentation faults, force memory disclosure, or bypass authentication mechanisms to gain unauthorized control over the device. Given the nature of these protection relays in energy sectors, successful exploitation could significantly impact operational availability and system integrity. Siemens has addressed these vulnerabilities in firmware version V2.70. Defenders are urged to prioritize patching to mitigate these risks.\u003c/p\u003e\n\u003cp\u003eThe full list of associated vulnerabilities includes: CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, and CVE-2026-62654.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in the denial of service of protective relay functions, unauthorized access to device management interfaces via authentication bypass, and potential disclosure of sensitive system memory. These devices are critical components of global energy infrastructure; disruption could degrade grid reliability or interrupt industrial control processes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Siemens Reyrolle 7SR5 devices to firmware version V2.70 or later immediately.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to restrict access to the web management interfaces of industrial control devices to authorized management segments only.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic directed at Siemens Reyrolle device management interfaces for anomalous TLS packet structures or unusual HTTP request patterns associated with the web server.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T16:31:59Z","date_published":"2026-09-15T16:31:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-siemens-reyrolle-vulnerabilities/","summary":"Siemens Reyrolle 7SR5 devices running firmware versions earlier than V2.70 are impacted by multiple vulnerabilities within the embedded Mongoose Web Server, potentially leading to denial of service, information disclosure, or authentication bypass.","title":"Multiple Vulnerabilities in Siemens Reyrolle 7SR5 Firmware","url":"https://feed.craftedsignal.io/briefs/2026-09-siemens-reyrolle-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:siemens:reyrolle_7sr5:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}