Impact
The flaw lies in the presence of debugging symbols in the firmware binaries of the Reyrolle 7SR5 device, all versions prior to V2.70. Because these symbols are not stripped, an attacker who obtains a firmware file could analyze the code more readily, which may reveal additional weaknesses or allow the creation of targeted exploits. The vulnerability therefore presents an information‑exposure risk that can lower the barrier to discovering new flaws, but it does not directly grant code execution or data exfiltration at the time of exploitation.
Affected Systems
Siemens Reyrolle 7SR5 devices running firmware versions older than V2.70 are impacted. Any installation of these firmware images, irrespective of configuration, maintains the debugging symbols that facilitate reverse engineering.
Risk and Exploitability
The CVSS score of 6.9 classifies the risk as medium. Without an EPSS value, the current exploitation probability cannot be quantified, but the KEV status confirms the vulnerability is not yet catalogued as a known exploited vulnerability. An unauthenticated attacker with access to the publicly available firmware update files—likely the download location—can exploit this weakness by reverse engineering; therefore the attack vector is inferable from the description. No known exploits or detailed attack paths have been reported at this time.
OpenCVE Enrichment