Status: UPDATED
| Advisory ID: CVE-2026-62646
Key Details
| CVE | CVE-2026-62646 |
| CVSS Score / Version | 7.4 (High) / CVSS v3.1 |
| Updated | 2026-09-10 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none. |
| Affected products | Siemens Reyrolle 7SR5 |
| Classified as | CWE-331 (Insufficient Entropy) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication. (NVD)
What to Do
Monitor Siemens's web page for any future patch releases.
References