Impact
A special maintenance mode in Reyrolle 7SR5 allows the device to download and run program code from a network server without validating authenticity or integrity. The vulnerability is triggered by a physical key sequence during boot, leading to arbitrary unsigned code execution on the device. The attacker can gain full control, compromising confidentiality, integrity, and availability of the device and any connected systems.
Affected Systems
Siemens Reyrolle 7SR5 devices with firmware versions lower than 2.70 are affected. This includes all variants released before the V2.70 update.
Risk and Exploitability
The CVSS score of 7 indicates high severity. EPSS is not available and the vulnerability is not listed in KEV. The attack requires physical access to the device during startup and knowledge of the maintenance mode key sequence. Once in the maintenance mode, the attacker can deliver and run arbitrary code from any network server that the device can reach.
OpenCVE Enrichment