Description
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential for future exploitation through reverse engineering
Action: Assess Impact
AI Analysis

Impact

The flaw lies in the presence of debugging symbols in the firmware binaries of the Reyrolle 7SR5 device, all versions prior to V2.70. Because these symbols are not stripped, an attacker who obtains a firmware file could analyze the code more readily, which may reveal additional weaknesses or allow the creation of targeted exploits. The vulnerability therefore presents an information‑exposure risk that can lower the barrier to discovering new flaws, but it does not directly grant code execution or data exfiltration at the time of exploitation.

Affected Systems

Siemens Reyrolle 7SR5 devices running firmware versions older than V2.70 are impacted. Any installation of these firmware images, irrespective of configuration, maintains the debugging symbols that facilitate reverse engineering.

Risk and Exploitability

The CVSS score of 6.9 classifies the risk as medium. Without an EPSS value, the current exploitation probability cannot be quantified, but the KEV status confirms the vulnerability is not yet catalogued as a known exploited vulnerability. An unauthenticated attacker with access to the publicly available firmware update files—likely the download location—can exploit this weakness by reverse engineering; therefore the attack vector is inferable from the description. No known exploits or detailed attack paths have been reported at this time.

Generated by OpenCVE AI on September 8, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to the latest firmware release that removes debugging symbols
  • Ensure firmware files are cryptographically signed and verify the signature before installation
  • Restrict public access to firmware update repositories so that only authenticated personnel can download images

Generated by OpenCVE AI on September 8, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens reyrolle 7sr5
Vendors & Products Siemens
Siemens reyrolle 7sr5

Tue, 08 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.
Weaknesses CWE-215
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Reyrolle 7sr5
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-09-10T18:18:25.117Z

Reserved: 2026-07-14T16:24:23.430Z

Link: CVE-2026-62652

cve-icon Vulnrichment

Updated: 2026-09-10T18:18:21.627Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T09:18:17.340

Modified: 2026-09-10T19:17:31.910

Link: CVE-2026-62652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:35:29Z

Weaknesses
  • CWE-215

    Insertion of Sensitive Information Into Debugging Code