Siemens Reyrolle 7SR5
View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7SR5 are affected: Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CVE-2026-62654) CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens Reyrolle 7SR5 Integer Overflow or Wraparound, Improper Neutralization of Delimiters, Use of Out-of-range Pointer Offset, Missing Authentication for Critical Function, Insufficient Entropy, Improper Input Validation, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Authentication Bypass Using an Alternate Path or Channel, Insertion of Sensitive Information Into Debugging Code, Download of Code Without Integrity Check Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2024-42384 Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. View CVE Details Affected Products Siemens Reyrolle 7SR5 Vendor: Siemens Product Version: Reyrolle 7SR5 < V2.70 Product Status: known_affected Remediations Vendor fix Update to V2.70 or later version https://support.industry.siemens.com/cs/ww/en/view/109772413/ Relevant CWE: CWE-190 Integer Overflow or Wraparound Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2024-42385 Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpe
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-05
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2024-423840.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-423850.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-423860.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-423910.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-423920.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-626450.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-626460.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-626470.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-626480.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-626490.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2024-42384 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-42385 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-42386 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-42391 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-42392 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62645 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62646 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62647 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62648 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62649 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62650 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62652 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62653 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62654 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedNCSC-2026-0346 [1.01] [M/H] Kwetsbaarheden verholpen in Siemens productenncsc-nl
- mediumCVE-2026-62654: A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special mainten…nvd
- mediumCVE-2026-62653: A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input receive…nvd
- mediumCVE-2026-62652: A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmwa…nvd
- highCVE-2026-62650: A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side autho…nvd
- highCVE-2026-62649: A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server do…nvd
- highCVE-2026-62648: A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the…nvd
- highCVE-2026-62647: A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number g…nvd
- highCVE-2026-62646: A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identif…nvd
- criticalCVE-2026-62645: A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is ex…nvd
More from CISA Cybersecurity Advisories
- criticalmySCADA myPRO Manager2026-09-15
- criticalSiemens Teamcenter2026-09-15
- criticalSiemens Mendix SAML2026-09-15
- criticalWärtsilä FOS-Onboard2026-09-15
- criticalDigital Watchdog VMAX DVR and NVR Product Lineups2026-09-15