Impact
A security flaw exists in Siemens Reyrolle 7SR5 versions prior to V2.70 where a random number generator is not seeded with a true random source, resulting in a predictable sequence of values used for session identifiers and other security‑related data. This flaw allows an attacker that does not possess credentials to anticipate future session tokens, thereby impersonating a legitimate authenticated user and gaining unauthorized access to the device. The weakness is identified as input validation/additional condition failure (CWE-20).
Affected Systems
Siemens Reyrolle 7SR5 devices running any firmware version earlier than V2.70 are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating critical severity. EPSS data is not available, but the absence of a KEV listing does not diminish the risk; remote attackers can exploit the flaw from outside the network. Attackers can generate enough session identifiers in a short period to brute‑force or predict valid tokens, leading to full impersonation of an authenticated session without needing to compromise other credentials. The flaw is exploitable over remote management interfaces, and no special privileges are required to start the attack.
OpenCVE Enrichment