Tec Nikan
فارسی
Talk to us
All news

Fourteen Flaws in a Substation Relay

Siemens has disclosed fourteen vulnerabilities in Reyrolle 7SR5 protection relays, led by a CVSS 9.8 in which information from the web interface can be used to calculate session IDs.

Siemensprotection relayssubstationsession managementCVE-2026-62645

Siemens ProductCERT published SSA-142885 on 8 September, listing fourteen vulnerabilities in Reyrolle 7SR5 protection relays across all versions prior to V2.70 — nine new 2026 CVEs plus five inherited from the Mongoose web server the device embeds. The headline is CVE-2026-62645 at CVSS v3.1 9.8 and v4.0 9.3: information exposed through the web interface can be used to calculate session IDs, allowing authentication bypass. Three related weaknesses compound it — CVE-2026-62646, insufficient randomness in session identifier generation, at 7.4 and 9.1; CVE-2026-62647, a random number generator used for security-relevant values that is not properly initialised, at 7.4 and 9.3; and CVE-2026-62650, an authorisation bypass letting a low-privilege authenticated user escalate, at 8.8 and 8.7. Two denial-of-service issues cover an out-of-bounds write from failed URL length validation and improper resource management under concurrent requests, both 7.5 and 8.7. CVE-2026-62652 notes debugging symbols left in firmware binaries. Two more need physical access: CVE-2026-62653, unvalidated input over a proprietary protocol exposed in firmware-update mode, and CVE-2026-62654, a maintenance mode activated by a physical key sequence at boot in which the device downloads and executes program code from a network server without verifying its authenticity or integrity. The remedy is V2.70 or later.

Read as a set rather than a list, these are one finding: the session management on this device was built on a random number generator that was not properly seeded. Predictable session identifiers, calculable session IDs and insufficient entropy are three descriptions of the same defect, which is why the CVSS v4.0 scores sit higher than the v3.1 ones on several of them — the newer framework is better at expressing that a single weakness yields full authentication bypass on a device with no other barrier.

CVE-2026-62654 deserves separate attention because it is a design decision rather than a coding error. A maintenance mode that fetches and runs unsigned code from the network is a deliberate feature, presumably for factory recovery, and it converts brief physical access to a relay into arbitrary firmware. Protection relays live in substations, which are locked but are visited by contractors, and this is exactly the kind of capability that should require a signature check rather than a key sequence.

For asset owners the sequence is straightforward and the urgency is real, because a protection relay is not an ordinary networked device: it is the thing that decides whether a breaker opens on a fault. Establish which 7SR5 units are below V2.70 and where their web interfaces are reachable from; the pre-authentication flaw means network exposure is the entire attack surface, so restricting the relay's HTTP access to a dedicated engineering network is the highest-value mitigation available before the firmware campaign completes. Then plan that campaign against the outage windows a substation actually has, and treat the physical-access findings as an argument for reviewing who holds keys rather than as a lower priority.

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.