CVE-2026-62646 PUBLISHED

Assigner: siemens
Reserved: 14.07.2026 Published: 08.09.2026 Updated: 08.09.2026

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.1

Product Status

Vendor Siemens
Product Reyrolle 7SR5
Versions Default: unknown
  • affected from 0 to V2.70 (excl.)

References

Problem Types

  • CWE-331: Insufficient Entropy CWE