Impact
An attacker can predict or brute‑force the session identifiers used by Reyrolle 7SR5, enabling a remote, unauthenticated user to inject a valid session cookie and bypass the login mechanism. The flaw originates from a deterministic algorithm that produces tokens with insufficient entropy, making the token guessable in a realistic number of attempts. Once an attacker obtains a valid session identifier, they can act with the privileges of the authenticated user. The weakness corresponds to CWE‑331 – Insufficient Entropy.
Affected Systems
All versions of Siemens Reyrolle 7SR5 prior to V2.70, as specified by the vendor.
Risk and Exploitability
The CVSS score of 9.1 indicates a high‑severity vulnerability. EPSS is not available, but the nature of the attack vector makes exploitation feasible for a motivated adversary. The vulnerability is not currently listed in CISA’s KEV catalog. Attackers with network access to the system can leverage the predictable session token to gain unauthorized control without needing credentials. Consequently, the risk remains high and exploitation is likely if no countermeasures are applied.
OpenCVE Enrichment