Impact
The Reyrolle 7SR5 web server fails to limit or manage system resources when it receives a large volume of concurrent HTTP requests, allowing an attacker to trigger a resource‑exhaustion condition that causes the device to crash and reboot. The result is a denial‑of‑service that interrupts all network connectivity to the device.
Affected Systems
Siemens Reyrolle 7SR5 units running any firmware version earlier than V2.70 are affected. No other vendors or product lines are implicated in this vulnerability.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7 and is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could use a sustained stream of HTTP requests from a remote network to exercise the flaw. Because the attack requires only generic network access and no credentials, the threat is significant for systems exposed to external traffic. Without a mitigating configuration or patch, the risk of a device‑wide denial of service remains high.
OpenCVE Enrichment