Siemens Reyrolle 7SR5
Siemens Reyrolle 7SR5 versions prior to V2.70 are vulnerable to multiple security flaws, including an integer overflow, improper neutralization of delimiters, and out-of-range pointer offsets. These vulnerabilities could allow an attacker to crash the device, execute arbitrary code, and potentially gain unauthorized access. Siemens has released a new version and recommends updating to V2.70 or later. The Reyrolle 7SR5 is used in critical infrastructure, particularly within energy systems worldwide. Operators should prioritize patching and implementing recommended security practices to mitigate the risk.
Siemens Reyrolle 7SR5 versions before V2.70 are affected by a series of security vulnerabilities. Siemens has released a new version for the device and strongly recommends that all users update to V2.70 or a later version to address these issues.
Several vulnerabilities exist within the Reyrolle 7SR5 firmware. These include:
- **Integer Overflow/Wraparound:** A vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet, leading to a segmentation fault.
- **Improper Neutralization of Delimiters:** Another vulnerability in Cesanta Mongoose Web Server v7.14 enables an attacker to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.
- **Use of Out-of-Range Pointer Offset:** This vulnerability allows an attacker to send an unexpected TLS packet and produce a segmentation fault.
- **Use of Out-of-range Pointer Offset:** This vulnerability allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
- **Improper Neutralization of Delimiters:** This vulnerability triggers an infinite loop bug if the input string contains unexpected characters.
- **Missing Authentication for Critical Function:** The device firmware contains binaries from which debugging symbols have not been removed, allowing an attacker to reverse engineer the device's firmware.
- **Download of Code Without Integrity Check:** A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server without verifying its authenticity or integrity.
- **Out-of-bounds Write:** A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server without verifying its authenticity or integrity.
- **Authentication Bypass Using an Alternate Path or Channel:** Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed.
- **Insertion of Sensitive Information Into Debugging Code:** The device firmware contains binaries from which debugging symbols have not been removed, allowing an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.
- **Allocation of Resources Without Limits or Throttling:** The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests, potentially causing a device crash.
- **Configuration of Sensitive Information:** A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.
The Reyrolle 7SR5 is commonly deployed in critical infrastructure sectors, particularly within energy systems worldwide. Siemens recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. As a general security measure Siemens strongly recommends protecting network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment. Recommended security guidelines can be found at: https://www.siemens.com/gridsecurity
CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. These include minimizing network exposure, isolating control systems networks, using VPNs, and implementing recommended cybersecurity strategies for proactive defense of ICS assets.