Full Report
Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Siemens Reyrolle 7SR5
## CVE Details
This advisory addresses multiple vulnerabilities. The most critical scores are highlighted below:
- **CVE IDs:** CVE-2026-62645 through CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CVE-2026-62654, CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392.
- **CVSS Score:** 9.8 (Critical) [CVSS v3.1] / 9.3 (Critical) [CVSS v4.0]
- **CWEs:**
- CWE-190 (Integer Overflow)
- CWE-823 (Out-of-range Pointer Offset)
- CWE-288 (Authentication Bypass)
- CWE-787 (Out-of-bounds Write)
- CWE-494 (Download of Code Without Integrity Check)
- CWE-215 (Sensitive Information in Debugging Code)
## Affected Systems
- **Products:** Reyrolle 7SR5 protection, control, and automation devices.
- **Versions:** All versions prior to V2.70.
- **Configurations:** Devices using the Cesanta Mongoose Web Server or exposed to proprietary communication protocols during firmware updates.
## Vulnerability Description
The Siemens Reyrolle 7SR5 series is affected by a suite of vulnerabilities ranging from third-party component flaws to proprietary protocol weaknesses.
- **Web Server Flaws:** Vulnerabilities in the Cesanta Mongoose Web Server (v7.14) allow for segmentation faults (DoS) via malformed TLS packets and out-of-bounds memory writes.
- **Authentication & Firmware:** The device contains an authentication bypass (CWE-288) and fails to remove debugging symbols, facilitating reverse engineering.
- **Physical/Maintenance Exploits:** A maintenance mode can be triggered via physical key sequences during boot that allows the device to execute unsigned code from a network server without integrity checks. Additionally, improper validation in firmware-update mode leads to memory corruption.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; no PoC provided in the advisory.
- **Complexity:** Ranges from Low (Network-based DoS/Auth Bypass) to High (Local/Physical access requirements for specific maintenance modes).
- **Attack Vector:** Multiple (Network, Adjacent, and Physical).
## Impact
- **Confidentiality:** High (Firmware reverse engineering and arbitrary code execution).
- **Integrity:** High (Execution of unsigned code and memory corruption).
- **Availability:** High (Device crashes and segmentation faults).
## Remediation
### Patches
- **Update to V2.70 or later.**
- Firmware can be obtained via the Siemens Industry Online Support portal: [https://support.industry.siemens.com/cs/ww/en/view/109772413/](https://support.industry.siemens.com/cs/ww/en/view/109772413/)
### Workarounds
- **Network Segmentation:** Protect network access using firewalls, VPNs, and VLAN segmentation.
- **Physical Security:** Restrict physical access to the devices to prevent exploitation of the maintenance mode and firmware-update sequences.
- **Redundancy:** Implement multi-level redundant secondary protection schemes to ensure grid resilience if one device is compromised.
## Detection
- **Indicators of Compromise:** Unexpected device reboots, unauthorized changes to device logic, or unrecognized network traffic originating from the device to external file servers.
- **Detection Methods:** Monitor network logs for unusual TLS packets or unauthorized attempts to access the device's web interface. Use industrial IDS to monitor for proprietary firmware-update protocol activity outside of maintenance windows.
## References
- **Vendor Advisory:** [https://cert-portal.siemens.com/productcert/pdf/ssa-142885.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-142885.pdf)
- **Siemens Grid Security Guidelines:** [https://www.siemens.com/gridsecurity](https://www.siemens.com/gridsecurity)
- **Siemens ProductCERT:** [https://www.siemens.com/cert/advisories](https://www.siemens.com/cert/advisories)