Executive brief
Siemens Reyrolle 7SR5 is a protection and control device used in electrical substations. The device uses a weak random number generator to create session identifiers for authentication, allowing attackers to predict valid session tokens and impersonate legitimate users without credentials, potentially compromising substation operations and grid stability.
Technical details
CVE-2026-62647 is an insufficient randomness vulnerability in the random number generator used to create session identifiers and other security-relevant values in Reyrolle 7SR5. The RNG is not initialized with a True Random Number Generator (TRNG), resulting in predictable sequences that can be derived or brute-forced by an unauthenticated remote attacker over the network. An attacker can predict session IDs and forge valid authentication tokens to gain unauthorized access to the device without needing legitimate credentials. The vulnerability affects all versions prior to V2.70, which includes the patch.
Affected products
- Siemens Reyrolle 7SR5 All versions < V2.70
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Update to V2.70 or later