A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens reyrolle 7sr5 |
|
| Vendors & Products |
Siemens
Siemens reyrolle 7sr5 |
Tue, 08 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Web Interface Session ID Disclosure Allows Authentication Bypass |
Tue, 08 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2026-09-08T08:11:22.667Z
Updated: 2026-09-08T12:26:29.371Z
Reserved: 2026-07-14T16:24:23.429Z
Link: CVE-2026-62645
Updated: 2026-09-08T12:26:19.024Z
Status : Deferred
Published: 2026-09-08T09:18:16.583
Modified: 2026-09-08T18:41:55.127
Link: CVE-2026-62645
No data.