Description
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device.
Published: 2026-09-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A security flaw exists in Siemens Reyrolle 7SR5 versions prior to V2.70 where a random number generator is not seeded with a true random source, resulting in a predictable sequence of values used for session identifiers and other security‑related data. This flaw allows an attacker that does not possess credentials to anticipate future session tokens, thereby impersonating a legitimate authenticated user and gaining unauthorized access to the device. The weakness is identified as input validation/additional condition failure (CWE-20).

Affected Systems

Siemens Reyrolle 7SR5 devices running any firmware version earlier than V2.70 are affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.3, indicating critical severity. EPSS data is not available, but the absence of a KEV listing does not diminish the risk; remote attackers can exploit the flaw from outside the network. Attackers can generate enough session identifiers in a short period to brute‑force or predict valid tokens, leading to full impersonation of an authenticated session without needing to compromise other credentials. The flaw is exploitable over remote management interfaces, and no special privileges are required to start the attack.

Generated by OpenCVE AI on September 8, 2026 at 09:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to version V2.70 or later, where a true random number generator is used.
  • Restrict or disable remote management interfaces and enforce strict network segmentation so only trusted devices can reach the Reyrolle 7SR5.
  • Continuously monitor authentication logs for abnormal session creation patterns and investigate any suspicious activity promptly.

Generated by OpenCVE AI on September 8, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Generation in Siemens Reyrolle 7SR5 Enables Authentication Impersonation

Tue, 08 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-09-08T08:11:24.801Z

Reserved: 2026-07-14T16:24:23.430Z

Link: CVE-2026-62647

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T09:18:16.840

Modified: 2026-09-08T09:18:16.840

Link: CVE-2026-62647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T09:30:07Z

Weaknesses
  • CWE-20

    Improper Input Validation