Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Predictable Session Identifier Generation in Siemens Reyrolle 7SR5 Enables Authentication Impersonation |
Tue, 08 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device. | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2026-09-08T08:11:24.801Z
Reserved: 2026-07-14T16:24:23.430Z
Link: CVE-2026-62647
No data.
Status : Deferred
Published: 2026-09-08T09:18:16.840
Modified: 2026-09-08T18:41:55.127
Link: CVE-2026-62647
No data.
OpenCVE Enrichment
Updated: 2026-09-08T09:30:07Z
-
CWE-20
Improper Input Validation