Impact
Memory corruption arises when the device processes data sent over its proprietary communication protocol while in firmware‑update mode. The lack of input validation can cause a crash and potentially allow an attacker to execute arbitrary code on the device.
Affected Systems
Siemens Reyrolle 7SR5, versions prior to V2.70 are vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability. EPSS data is not available, and the issue is not in the CISA KEV catalog, but the need for physical, unauthenticated access means the attack requires proximity to the device. If an attacker can trigger the firmware‑update mode, the exploit path is straightforward and could lead to compromise of the firmware executor and subsequent code execution.
OpenCVE Enrichment