CVE-2026-62647
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authenticat...
Affects 0 products across 1 vendor.
Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.
Show all 51
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A high severity vulnerability (CVE-2026-62647) affects the target system. A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Ran...
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-62647?
What is the CVSS score for CVE-2026-62647?
Is CVE-2026-62647 actively exploited?
How do I remediate CVE-2026-62647?
What systems are affected by CVE-2026-62647?
| CVE ID | CVE-2026-62647 |
|---|---|
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| Published | 2026-09-08 |
| Last Modified | 2026-09-15 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Source | NVD |
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device.
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Fixed Version |
|---|---|---|
| Siemens | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Monitoring Siemens Vulnerabilities in Your Environment?
BreachSpider tracks every Siemens CVE and maps them to your ICS assets automatically. Get email or webhook alerts when a newly published Siemens vulnerability matches your assets.
Create a free account →