Impact
Server‑side authorization checks in the Reyrolle 7SR5 web‑based management interface are not properly enforced. This flaw lets a malicious user manipulate request data to bypass role‑based access control (RBAC), enabling a low‑privileged authenticated user to elevate privileges to an administrative level. The impact is pure privilege escalation, compromising confidentiality, integrity, and availability of the device for the attacker who can then perform any action permitted to an administrator.
Affected Systems
Siemens Reyrolle 7SR5 devices running any software version older than V2.70 are affected. Users of earlier releases should verify their firmware version and plan an update as soon as possible.
Risk and Exploitability
The CVSS base score of 8.7 classifies this flaw as high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating a lack of public exploit evidence at this time. The attack requires the attacker to be authenticated with a low‑privilege account, after which they can craft specific web requests to exploit the missing server‑side authorization. Because the flaw is in the web interface, it can be exploited remotely over the network if the interface is reachable.
OpenCVE Enrichment