Impact
Reyrolle 7SR5 fails to validate the length of the URL component in pre‑authenticated HTTP messages before appending additional data. This missing validation results in an out‑of‑bounds write for an attacker who supplies an excessively long URL component, causing a memory corruption that crashes the HTTP stack and forces the device to reboot. The crash precludes normal operation and constitutes a denial‑of‑service.
Affected Systems
Siemens Reyrolle 7SR5, all firmware versions prior to V2.70 are affected.
Risk and Exploitability
The CVSS score is 8.7, indicating a high‑severity vulnerability. EPSS information is not available, and the flaw is not listed in CISA’s KEV catalog. The attack vector requires an unauthenticated HTTP connection; no credentials or privileged access are needed. A remote attacker can simply send a crafted HTTP request to trigger the overflow, which typically results in a device reboot and service interruption.
OpenCVE Enrichment