Multiple Vulnerabilities in Reyrolle 7SR5 Before V2.70

Plan PatchCVSS 9.8SSA-142885Sep 8, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Siemens Reyrolle 7SR5 before version V2.70 is affected by multiple vulnerabilities including integer overflow, memory corruption, improper input validation, missing authentication checks, weak random number generation, and insecure deserialization. These vulnerabilities could allow remote code execution and manipulation of relay protection logic without authentication.

What this means
What could happen
Multiple vulnerabilities in the Reyrolle 7SR5 relay could allow an attacker to remotely execute commands, modify protective relay settings, or disrupt power system protection operations.
Who's at risk
Electric utilities and substations operating Reyrolle 7SR5 protective relays for transmission and distribution line protection, transformer protection, and generator protection. This device is critical to power system stability and fault isolation.
How it could be exploited
An attacker with network access to the 7SR5 device could exploit one or more of the identified vulnerabilities to execute arbitrary code or manipulate relay logic without requiring authentication, potentially altering trip setpoints or disabling protection functions.
Prerequisites
  • Network access to the Reyrolle 7SR5 device
  • Device running firmware version prior to V2.70
remotely exploitableno authentication requiredlow complexityaffects safety systemshigh CVSS score (9.8)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (1)
ProductAffected VersionsFix Status
Reyrolle 7SR5 < V2.70< 2.702.70
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Reyrolle 7SR5 to firmware version V2.70 or later
API: /api/v1/advisories/2f6cc0d7-8e3e-4827-a286-e49c3d4acb93

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Multiple Vulnerabilities in Reyrolle 7SR5 Before V2.70 | CVSS 9.8 - OTPulse