Siemens Reyrolle 7SR5
September 15, 2026 · CISA (US-CERT) · Severity: CRITICAL
Siemens has disclosed multiple vulnerabilities affecting its Reyrolle 7SR5 protection relays running versions prior to V2.70. The vulnerabilities include integer overflow or wraparound, improper neutralization of delimiters, use of out-of-range pointer offsets, missing authentication for critical functions, insufficient entropy, improper input validation, out-of-bounds writes, allocation of resources without limits, authentication bypass, insertion of sensitive information into debugging code, and download of code without integrity check. With a CVSS score of 9.8, these vulnerabilities pose significant risk to energy sector infrastructure worldwide. Siemens recommends updating to V2.70 or later to remediate these issues.
Key Takeaways
- Siemens Reyrolle 7SR5 relays running versions below V2.70 are affected by 14 distinct vulnerabilities including integer overflows, authentication bypass, and out-of-bounds write flaws.
- The most severe vulnerabilities carry a CVSS v3 base score of 9.8, reflecting the critical risk they pose to energy sector infrastructure deployed worldwide.
- Multiple vulnerabilities stem from the Cesanta Mongoose Web Server component, including integer overflow allowing segmentation faults via unexpected TLS packets.
- Siemens has released version V2.70 and urges all customers operating Reyrolle 7SR5 relays to update immediately to mitigate exploitation risks.