Sceawere

Vulnerability Detail

CVE-2026-62649UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reyrolle 7SR5 Denial-of-Service Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Siemens
Product
Reyrolle 7SR5
Attack Type
CWE-770: Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire device to crash and reboot, resulting in a denial-of-service condition.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-08T09:18:17.093Z",
  "pubdate": "2026-09-08T09:18:17.093Z",
  "executiveSummary": "A resource management vulnerability exists in the web server component of Reyrolle 7SR5 devices (versions prior to V2.70). The vulnerability stems from the system's inability to effectively limit or manage system resources during periods of high-volume, concurrent HTTP request traffic.\nThe primary impact of this flaw is a Denial-of-Service (DoS) condition, where the targeted device experiences a system-wide crash followed by an automatic reboot. This event results in temporary loss of device availability and functionality.\nThe vulnerability is exploitable by an unauthenticated remote attacker who does not require prior system privileges. Successful exploitation is contingent on the attacker's ability to transmit a sufficient volume of HTTP requests to overwhelm the device's web server resources.\nGiven the nature of the device as a protective relay or industrial component, the potential for forced reboots represents a significant risk to operational continuity and system reliability. Organizations should prioritize updating to V2.70 or higher to mitigate this exposure.",
  "technicalDetails": "The vulnerability is localized within the web server service responsible for handling HTTP communication in Reyrolle 7SR5 devices. The root cause is an absence of robust rate limiting, request queuing, or resource throttling mechanisms within the server's request-processing logic. When the service is subjected to a high volume of concurrent HTTP requests, it fails to allocate or manage memory and CPU cycles efficiently, leading to resource exhaustion.\nThe exploitation process involves an unauthenticated remote actor initiating a sustained flood of HTTP requests towards the device's web management interface. Because the web server lacks sufficient resource bounds, each concurrent connection consumes finite system resources—such as memory buffers, thread pools, or process handles—without being appropriately cleared or prioritized. As the attacker maintains this high request rate, the system reaches a critical threshold where resource starvation occurs.\nUpon reaching this state of exhaustion, the web server process, and potentially the underlying firmware environment, becomes unresponsive. The kernel or watchdog mechanism governing the device's stability detects the failure or critical resource depletion, triggering a kernel panic or an unrecoverable exception. This subsequently forces the device to execute a hard reboot cycle to restore the system to a functional state. The attack flow is characterized by the following steps: (1) Reconnaissance to identify the web management service; (2) Preparation of a traffic generator capable of parallelizing numerous HTTP requests; (3) Execution of a high-concurrency attack targeting the web port; (4) Observation of device hang and subsequent system reboot; (5) Repeat cycle to maintain a persistent denial-of-service condition.\nThe vulnerability affects all Reyrolle 7SR5 versions earlier than V2.70. Since the flaw resides in the web server implementation, it is exposed over the network, making it accessible to any actor capable of reaching the device's HTTP management interface. No authentication is required to initiate the resource exhaustion, as the crash occurs during the initial phases of the connection handling process, before authentication logic is typically invoked."
}
CVE-2026-62649: Reyrolle 7SR5 Denial-of-Service Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere