Impact
A vulnerability in the Reyrolle 7SR5 web interface allows an attacker to read and calculate current and past session ID numbers, which can be used to bypass device authentication and gain unauthorized access. The weakness permits an end user to acquire credentials that normally require a password, enabling full control over the device without legitimate login. The impact is a complete compromise of device security, exposing all configuration and operational controls to the attacker.
Affected Systems
Siemens Reyrolle 7SR5, all firmware versions less than V2.70. Any device running these versions is vulnerable because the web interface fails to protect session identifiers from disclosure.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity vulnerability. EPSS data is not available, and the CVE is not listed in the CISA KEV catalog, suggesting fewer publicly known exploits. The likely attack vector is over the network via the web interface; the attacker must obtain or compute a valid session ID to authenticate. No additional exploitation prerequisites are mentioned beyond accessing the web interface, so the vulnerability is exploitable by any entity that can reach the device over the network.
OpenCVE Enrichment