Critical Flaw in Siemens Reyrolle Grid Protection Relays Allows Authentication Bypass

Electrical substation protected by security and condition-monitoring systems

CISA published an advisory disclosing 14 vulnerabilities in Siemens Reyrolle 7SR5 protection relays, devices used in electrical substations worldwide to detect faults and trigger circuit breakers. The most severe, CVE-2026-62645, carries a CVSS score of 9.8 out of 10 and stems from the relay’s web interface exposing information that lets an attacker calculate current and past session IDs — enough to bypass authentication entirely without any privileges or user interaction.

The advisory also describes a related flaw allowing predictable session-ID generation from insufficient entropy, an out-of-bounds write reachable through crafted URLs that can force the device to reboot, and a physical-access vector that could allow unsigned code execution through a maintenance-mode key sequence. Siemens has released firmware version 2.70 to address the vulnerabilities; earlier versions remain exposed.

Why it matters

Protection relays are a core safety component of the electrical grid — an attacker who can bypass authentication on one gains the ability to interfere with fault detection and circuit-breaker operation, which is exactly the kind of access that grid-security planners worry about most.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *