Vulnerability in Reyrolle 7SR5 Affecting Security Token Generation
CVE-2026-62647

9.3CRITICAL

Key Information:

Vendor

Siemens

Vendor
CVE Published:
8 September 2026

What is CVE-2026-62647?

A vulnerability has been detected in Reyrolle 7SR5 where the security features rely on a random number generator that is not properly initialized with a True Random Number Generator (TRNG). This can result in a predictable sequence of values, such as session identifiers, which may allow unauthorized attackers to predict and replicate these values. Consequently, an attacker could impersonate legitimate users and gain unauthorized access to the device, presenting significant security risks.

Affected Version(s)

Reyrolle 7SR5 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.