Executive brief
Reyrolle 7SR5 is a protection and control device used in electrical substations. A flaw in its web server allows an unauthenticated attacker on the network to crash the entire device and force it to reboot by sending a high volume of concurrent HTTP requests, causing a denial-of-service condition that disrupts critical grid infrastructure.
Technical details
The web server fails to properly limit or manage system resources when processing a high volume of concurrent HTTP requests. An unauthenticated remote attacker can exploit this denial-of-service vulnerability via network access without authentication or user interaction. By sending a flood of concurrent HTTP requests, an attacker can exhaust system resources, causing the device to crash and reboot. The vulnerability affects all versions prior to V2.70; Siemens has released patches and recommends immediate update to V2.70 or later.
Affected products
- Siemens Reyrolle 7SR5 All versions < V2.70
Timeline
- 2026-09-08: disclosed