Multiple Vulnerabilities in Reyrolle 7SR5 Before V2.70
Plan PatchCVSS 9.8SSA-142885Sep 8, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Siemens Reyrolle 7SR5 before version V2.70 is affected by multiple vulnerabilities including integer overflow, memory corruption, improper input validation, missing authentication checks, weak random number generation, and insecure deserialization. These vulnerabilities could allow remote code execution and manipulation of relay protection logic without authentication.
What this means
What could happen
Multiple vulnerabilities in the Reyrolle 7SR5 relay could allow an attacker to remotely execute commands, modify protective relay settings, or disrupt power system protection operations.
Who's at risk
Electric utilities and substations operating Reyrolle 7SR5 protective relays for transmission and distribution line protection, transformer protection, and generator protection. This device is critical to power system stability and fault isolation.
How it could be exploited
An attacker with network access to the 7SR5 device could exploit one or more of the identified vulnerabilities to execute arbitrary code or manipulate relay logic without requiring authentication, potentially altering trip setpoints or disabling protection functions.
Prerequisites
- Network access to the Reyrolle 7SR5 device
- Device running firmware version prior to V2.70
remotely exploitableno authentication requiredlow complexityaffects safety systemshigh CVSS score (9.8)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (1)
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Reyrolle 7SR5 to firmware version V2.70 or later
CVEs (14)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/2f6cc0d7-8e3e-4827-a286-e49c3d4acb93Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.