Sceawere

Vulnerability Detail

CVE-2026-62653UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reyrolle 7SR5 Memory Corruption Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
3h ago
Vendor
Siemens
Product
Reyrolle 7SR5
Attack Type
CWE-787: Out-of-bounds Write
Vector String
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is placed into a special firmware-update mode is not properly validated, resulting in a memory corruption condition. This could allow an unauthenticated attacker with physical access to the device to cause a crash and potentially execute arbitrary code on the device.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-09-08T09:18:17.463Z",
  "pubdate": "2026-09-08T09:18:17.463Z",
  "executiveSummary": "A memory corruption vulnerability has been identified in Reyrolle 7SR5 protection relays (all versions prior to V2.70). The flaw exists within the proprietary communication protocol processing logic utilized during the device's specialized firmware-update mode.\nThe vulnerability allows an unauthenticated attacker with physical access to the device to trigger a memory corruption condition by sending malformed input to the device while in the restricted update state.\nSuccessful exploitation of this flaw can result in a denial-of-service (DoS) condition via device crash or potentially allow for arbitrary code execution, which could compromise the operational integrity of the relay.\nThe primary risk implication is the potential for unauthorized control or interruption of critical protective functions. Exploitation requires physical access to the device interfaces to interact with the firmware-update protocol, limiting the attack surface to individuals with proximity to the hardware.",
  "technicalDetails": "The vulnerability resides in the input validation routines of the proprietary communication protocol implementation on Reyrolle 7SR5 devices. When the device is transitioned into firmware-update mode, it initiates a listening state for specific update-related packets. The vulnerability is triggered when the device receives packets that violate the expected structural or length constraints defined by the proprietary protocol.\nThe root cause is identified as improper sanitization or bounds checking of input data handled by the firmware-update service. Because the device fails to validate the integrity and size of incoming data packets against allocated memory buffers, an attacker can craft specifically malformed packets designed to induce a buffer overflow or an out-of-bounds memory access.\nThe attack flow proceeds as follows: First, the attacker gains physical access to the device and triggers the transition to firmware-update mode, which exposes the vulnerable protocol interface. Second, the attacker transmits a sequence of specially crafted packets that contain payloads exceeding the capacity of the target memory buffer. Third, the processing of this payload overwrites adjacent memory structures, such as stack frames, return pointers, or control blocks.\nIf the corruption overwrites critical return addresses or function pointers, the execution flow of the processor can be hijacked. Given the nature of the firmware-update state, the device is operating with elevated privileges, typically running as the root or kernel-level process responsible for hardware abstraction and update operations. Consequently, arbitrary code execution in this context would grant the attacker control over the device's firmware update logic, potentially allowing for the installation of malicious firmware images.\nThe vulnerability is present in all firmware versions preceding V2.70. Since the protocol is exclusively exposed during the firmware-update mode, standard network-based remote exploitation is mitigated; however, the lack of authentication during this state allows any party with physical access to initiate the attack sequence. The post-exploitation impact includes persistent compromise of the relay, potential bypass of safety interlocking mechanisms, or complete loss of function, necessitating manual recovery or authorized re-flashing of the device."
}
CVE-2026-62653: Reyrolle 7SR5 Memory Corruption Vulnerability (MEDIUM Severity, CVSS: 6.8) - Sceawere