TroutTrout
Back to Blog
ICS AdvisoriesPower GridNERC CIPOT Remote AccessEnergy

Siemens Reyrolle 7SR5 Relays: What to Do Before You Patch

Trout Team10 min read

The short version.

On September 15, 2026, CISA published ICSA-26-258-05 for Siemens Reyrolle 7SR5 protection relays. It republishes Siemens advisory SSA-142885, first published on September 8. It covers 14 CVEs in every version before V2.70.

The most severe is CVE-2026-62645, CVSS v3.1 9.8. The relay's web interface exposes information that lets an attacker calculate current and past session IDs. With a valid session ID, the attacker skips the login. Other flaws let an attacker with no login crash the web server. The fix is firmware V2.70 or later.

Relay firmware needs bench testing and an outage plan. Most fleets will not be patched this month. Until they are, the job is to control who can reach the relay's web interface. Neither advisory mentions known exploitation.

Why a protection relay matters.

A protection relay watches current and voltage on a line, feeder or transformer. When it sees a fault, it trips the breaker. That clears a short circuit before it damages equipment or spreads across the network.

The relay's settings decide when it trips. Bad settings can open a breaker for no reason and drop customers. They can also leave a breaker closed during a fault. That makes the relay's management interface one of the most sensitive logins in a substation.

Siemens adds one line for power systems. It recommends "multi-level redundant secondary protection schemes" for critical systems. In plain terms, no single relay should be the only thing between a fault and an outage.

What the advisory says.

  • Product: Siemens Reyrolle 7SR5, all versions before V2.70.
  • Fix: V2.70 or later, from the Siemens support portal.
  • Sector: Energy, deployed worldwide.
  • Known exploitation: not mentioned by CISA or Siemens.
CVECVSS v3.1What it allows, per SiemensAccess needed
CVE-2026-626459.8Web interface leaks data used to calculate current and past session IDsNetwork, no login
CVE-2026-626467.4Session IDs with too little entropy, open to prediction or brute forceNetwork, no login, high complexity
CVE-2026-626477.4Badly initialized random number generator for security tokensNetwork, no login, high complexity
CVE-2026-626508.8Role-based access control bypass, privilege escalation to adminNetwork, low-privilege login
CVE-2026-626487.5Unchecked URL length, out-of-bounds write, device crashNetwork, no login
CVE-2026-626497.5Web server runs out of resources under many requestsNetwork, no login
CVE-2024-423847.5Integer overflow in the Mongoose web server, crashNetwork, no login
CVE-2024-423868.2Out-of-range pointer offset in TLS processingNetwork, no login
CVE-2024-423854.0Delimiter flaw leading to out-of-bounds writeLocal, high privileges
CVE-2024-423914.3Pointer offset flaw exposing heap memoryNetwork, user interaction
CVE-2024-423924.0Infinite loop on unexpected inputLocal, high privileges
CVE-2026-626525.3Debug symbols left in firmware, easier reverse engineeringAccess to firmware files
CVE-2026-626536.8Memory corruption in firmware-update modePhysical
CVE-2026-626546.8Unsigned code execution through a maintenance modePhysical

The five 2024 CVEs sit in Mongoose, the open-source embedded web server inside the relay. Access needed comes from the CVSS v3.1 vectors in SSA-142885. Seven flaws let an attacker with no login reach the relay over the network, most of them through the web interface.

What an attacker can do through the web interface.

The network flaws fall into three groups.

Session takeover. CVE-2026-62645, -62646 and -62647 all weaken the session ID. A session ID is the token that proves you already logged in. If an attacker can calculate or guess it, the password stops mattering.

Privilege escalation. CVE-2026-62650 lets a user with a low-privilege account bypass role checks and act as an admin. Every relay account becomes a possible admin account.

Denial of service. CVE-2026-62648, CVE-2026-62649 and the Mongoose flaws can crash the web server or the device. The advisories do not say whether a crash interrupts the protection functions. Test that on a bench relay before you assume either answer.

The table below maps the flaws to MITRE ATT&CK for ICS. It describes what the flaws allow. It does not describe an observed attack.

TacticTechnique (ID)How it applies here
Initial AccessExploitation of Remote Services (T0866)Session ID flaws bypass the web login
Initial AccessInternet Accessible Device (T0883)Only if the web interface is reachable from the internet
Privilege EscalationExploitation for Privilege Escalation (T0890)CVE-2026-62650 turns a low-privilege user into an admin
Inhibit Response FunctionDenial of Service (T0814)URL, resource and Mongoose flaws crash the web server or device
Impair Process ControlModify Parameter (T0836)Possible with an admin session, if your firmware lets the web interface change settings
PersistenceSystem Firmware (T0857)CVE-2026-62654, unsigned code in maintenance mode, physical access needed
ImpactLoss of Protection (T0837)Worst case, if a crash or settings change stops the relay from tripping

How long relay patching takes.

A relay update is a field job. Each relay is taken out of service, updated and tested again, often on a scheduled outage or with backup protection covering the bay.

The steps are familiar to any protection team. Read the release notes. Check that your settings files carry over to V2.70. Test the update on a bench relay. Plan the switching. Update, then run the functional checks again. Update the configuration baseline.

Across a fleet spread over many substations, that takes months. Plan for the gap between the advisory and the last updated relay.

NERC CIP builds that gap in. For medium and high impact systems, CIP-007-6 R2 asks you to evaluate a security patch, then, within 35 days, apply it or write a dated mitigation plan. The controls in the next sections are what goes in that plan. CIP-010 also treats firmware as part of the baseline, so the update follows your change process.

What NERC CIP asks for at the relay.

Which standard applies depends on the impact rating under CIP-002 of the system the relay belongs to. Many distribution and smaller transmission substations are low impact.

ControlRequirementApplies to
Allow only needed inbound and outbound access, deny the restCIP-005-7 R1.3Medium and high impact
Interactive remote access through an Intermediate System, encrypted, with MFACIP-005-7 R2.1 to R2.3Medium and high impact
See and cut active vendor remote sessionsCIP-005-7 R2.4 and R2.5Medium and high impact
Enable only the ports and services you needCIP-007-6 R1.1Medium and high impact
Patch or write a dated mitigation planCIP-007-6 R2Medium and high impact
Limit electronic access to what is necessaryCIP-003-9 Attachment 1, Section 3Low impact
Control vendor electronic remote access, since April 1, 2026CIP-003-9 Attachment 1, Section 6Low impact

Our NERC CIP compliance guide covers the evidence each requirement needs.

What to do before you can patch.

Start with the vendor's own steps. Siemens and CISA both say to keep the relay off the internet. Put it behind firewalls and away from the business network. Use a secure remote access method when remote access is needed. Follow the Siemens operational guidelines for grid security, and do an impact analysis before you change anything.

Then limit who can reach the web interface. The relay's protection protocols and its web interface do different jobs. SCADA needs to poll the relay. Very few people need its web pages. Allow the web interface only from named engineering workstations. Block it from everyone else on the substation and corporate networks.

Tie each session to a person. Every engineer signs in with their own account and MFA before reaching a relay. Every session is recorded. A session ID flaw then only helps someone who already passed that check.

Review relay accounts. CVE-2026-62650 turns a low-privilege account into an admin. Remove shared and unused accounts.

Watch for crashes. A relay web server that restarts for no reason, or a burst of HTTP requests, is worth a call to the substation team.

How Access Gate helps, and its limits.

Two panels. Today: engineers, vendors and an attacker on the substation network can all reach the Reyrolle 7SR5 web interface. With Access Gate: only a named engineer with MFA and a recorded vendor session reach the relay, everyone else has no route.
Who can reach the Reyrolle 7SR5 web interface today, and with a gate while V2.70 is tested.

Access Gate is an appliance installed at each site. It connects beside the existing substation network. You then steer relay web traffic through it, one relay or one subnet at a time. Nothing is installed on the relays. It is installed in a day per site.

Once traffic flows through the gate, the relay web interface answers only named engineers. Each one signs in with MFA and reaches only the relays the job needs. Each session is recorded. A vendor gets a time-limited session that you can see and cut. SCADA polling keeps its existing path. The access logs and recordings are the evidence for CIP-005-7 R2 and CIP-003-9 Section 6. See secure remote access and power grid security for how this works at a substation.

The limits are real. Access Gate does not fix the firmware. An engineer who is allowed in still reaches a vulnerable web server. Someone already plugged into the substation switch behind the gate is outside its control. The two physical-access flaws need locks and site security. V2.70 is still the fix. The gate controls who reaches the relays until every one runs it.

What to do this week.

  1. List every Reyrolle 7SR5 relay and its firmware version.
  2. Test who can reach each web interface, from the corporate network and from the internet.
  3. Restrict the web interface to named engineering workstations.
  4. Remove shared and unused relay accounts.
  5. Download V2.70 and start the bench test.
  6. Write the mitigation plan for relays you cannot update within 35 days.
  7. Check physical security at substations with 7SR5 relays.

Want to see where a gate would sit in your substation? Build your network in a few minutes. Every other advisory we have covered is in the ICS security advisories archive.


Sources: CISA ICS Advisory ICSA-26-258-05 (September 15, 2026), Siemens ProductCERT SSA-142885 (September 8, 2026), Siemens operational guidelines for grid security, and the NERC CIP-003-9, CIP-005-7 and CIP-007-6 standards. Verify affected and fixed versions against SSA-142885 before scheduling work.

FAQ

Frequently Asked Questions

What is CISA advisory ICSA-26-258-05?
It is an ICS advisory CISA published on September 15, 2026 for Siemens Reyrolle 7SR5 protection relays. It republishes Siemens advisory SSA-142885, first published on September 8, 2026. It covers 14 CVEs in all 7SR5 versions before V2.70. The highest score is CVSS v3.1 9.8, for CVE-2026-62645. The sector is Energy, and the product is deployed worldwide.
What does CVE-2026-62645 allow on a Reyrolle 7SR5 relay?
According to Siemens, the relay's web interface exposes information that can be used to calculate current and past session ID numbers. An attacker who can reach the web interface can use a calculated session ID to bypass authentication and gain access to the device. It scores CVSS v3.1 9.8, which means it is reachable over the network, with low complexity, and with no login.
Which Reyrolle 7SR5 versions are fixed?
Version V2.70 and later fix all 14 CVEs. Every version before V2.70 is affected. Siemens provides the update through its support portal and recommends validating it before deployment. The CISA advisory links to the same download.
Is ICSA-26-258-05 being exploited?
Neither the CISA advisory nor Siemens SSA-142885 mentions known exploitation. The CISA advisory makes no Known Exploited Vulnerabilities claim for these CVEs. That can change, so check the CISA KEV catalog before you set the priority of the update.
Do the Reyrolle 7SR5 flaws need physical access?
Two of them do. CVE-2026-62653, memory corruption in firmware-update mode, and CVE-2026-62654, unsigned code execution through a maintenance mode, both need physical access to the relay. The session ID flaws, the access control bypass and the denial-of-service flaws in the web server are reachable over the network.
How does NERC CIP apply to an unpatched protection relay?
It depends on the impact rating of the BES Cyber System the relay belongs to. For medium and high impact systems, CIP-007-6 R2 lets you apply the patch or write a dated mitigation plan within 35 days of evaluating it, and CIP-005-7 controls electronic access to the relay. For low impact assets, CIP-003-9 requires electronic access controls and, since April 1, 2026, controls on vendor electronic remote access.