Executive brief
Siemens Reyrolle 7SR5 is a protection and automation device used in electrical substations. Firmware update files contain debugging symbols that were not removed during compilation, allowing an attacker with access to public firmware downloads to more easily reverse engineer the device and discover additional security flaws without needing a valid account or physical access.
Technical details
The vulnerability is classified as improper information exposure through debug symbols left in firmware binaries (CWE-1104/CWE-11). An unauthenticated attacker can obtain the publicly available firmware update files and extract debugging symbols from compiled binaries, significantly reducing the complexity and time required for reverse engineering. Debug symbols provide function names, variable names, and source-level structure information that facilitate vulnerability research. The attack requires only file-system access to the firmware package—no authentication or network connectivity is needed. Patches were released in V2.70 and later versions.
Affected products
- Siemens Reyrolle 7SR5 All versions before V2.70
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Fix released in V2.70