PatchSiren cyber security CVE debrief
CVE-2026-62647 Siemens CVE debrief
A vulnerability in Reyrolle 7SR5 devices could allow an unauthenticated remote attacker to predict generated security-relevant values, potentially gaining unauthorized access. This critical vulnerability affects devices with versions prior to V2.70 and could enable attackers to impersonate legitimate authenticated users, leading to unauthorized access and potential disruptions to device operations. Defenders should prioritize inventory checks, remediation, and compensating controls to mitigate the risk.
- Vendor
- Siemens
- Product
- Reyrolle 7SR5
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-08
Who should care
Defenders responsible for Reyrolle 7SR5 devices, security teams, and network administrators should prioritize inventory checks, remediation, and compensating controls to mitigate the risk. They should also verify the authenticity of users and sessions, and implement compensating controls to monitor and restrict access to the devices. Additionally, they should review and update security configurations to prevent unauthorized access, conduct regular security
Why it matters
CVE-2026-62647 is a critical vulnerability in Reyrolle 7SR5 devices that could allow unauthenticated remote access. Defenders should prioritize inventory checks, remediation, and compensating controls to mitigate the risk.
- Potential unauthorized access to the device
- Need for verification of user and session authenticity
- Possible impersonation of legitimate authenticated users
Technical summary
The Reyrolle 7SR5 device uses a random number generator that is not initialized with a True Random Number Generator (TRNG), resulting in predictable generated values. This could allow an unauthenticated remote attacker to impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device. The vulnerability affects devices with versions prior to V2.70 and could enable attackers to predict generated security-relevant values, leading to unauthorized access and potential disruptions to device operations.
Defensive priority
High priority for inventory checks and remediation
Recommended defensive actions
- Inventory Reyrolle 7SR5 devices and check for version V2.70 or later
- Implement compensating controls to monitor and restrict access to the devices
- Verify the authenticity of users and sessions
- Review and update security configurations to prevent unauthorized access
- Conduct regular security audits to identify potential vulnerabilities
- Monitor device logs for suspicious activity
- Develop an incident response plan in case of a security breach
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but information on affected versions and remediation is limited. The Reyrolle 7SR5 device uses a random number generator that is not initialized with a True Random Number Generator (TRNG), resulting in predictable generated values. Defenders should verify the authenticity of users and sessions, and implement compensating controls to monitor and restrict access to the devices.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-62647 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-62647
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-62647 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62647
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-142885.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.