CVE-2026-62645 PUBLISHED

Assigner: siemens
Reserved: 14.07.2026 Published: 08.09.2026 Updated: 08.09.2026

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Siemens
Product Reyrolle 7SR5
Versions Default: unknown
  • affected from 0 to V2.70 (excl.)

References

Problem Types

  • CWE-306: Missing Authentication for Critical Function CWE