Executive Summary
CVE-2026-62650 is a server-side authorization flaw in the web-based management interface of Siemens Reyrolle 7SR5 protection relays (all versions before V2.70) that lets an authenticated low-privilege remote attacker manipulate request data to bypass role-based access control and gain administrative rights. Because these devices provide protection functions for power distribution and transmission assets, a privilege escalation on the relay places direct control of trip logic, protection settings, and configuration in the hands of an attacker.
Technical Exposure Breakdown
The defect sits in the authorization layer of the device web interface. Authentication is enforced, but the server does not consistently re-validate the caller's role against the requested action. The advisory characterizes this as authorization checks that are not properly enforced, allowing RBAC restrictions to be bypassed through manipulation of request data. In practical terms, a session that logged in with a read-only or operator-tier account can craft or modify requests referencing privileged endpoints or parameters, and the server processes them as though an administrator issued them.
This is a classic broken access control pattern where the client-supplied role indicator or resource identifier is trusted rather than the server-side session context. The attack precondition is low: valid low-privilege credentials and network reachability to the web interface. No memory corruption, no chained exploit, and no physical access are described. The CVSS score of 8.8 reflects that low barrier combined with a full compromise of confidentiality, integrity, and availability once escalation succeeds.
The key detail for defenders is that this attacker is already inside the trust boundary. Shared operator accounts, default engineering credentials, and contractor logins that were never rotated all become escalation paths. On a protection relay, an administrative session is the difference between reading a setting and changing the pickup threshold that decides whether a fault trips a breaker.
OT Impact and Compliance Risk
Reyrolle 7SR5 devices sit at the protection layer of substation and distribution automation. An attacker with administrative access can alter protection setpoints, disable elements, modify trip characteristics, or push configuration that leaves feeders unprotected during a fault. The physical outcome ranges from nuisance trips and unnecessary outages to suppressed protection that allows equipment damage during an actual fault condition. This is not data theft, it is manipulation of the logic that keeps switchgear and transformers within safe operating limits.
For NERC CIP registered entities, a relay of this class is frequently a medium or high impact BES Cyber Asset. A defect that permits privilege escalation directly implicates CIP-005 electronic access controls and CIP-007 account and access management. Under IEC 62443, this is a failure of the SR 1.x identification and authentication and SR 2.1 authorization enforcement requirements at the device level, and it undermines any zone and conduit model that assumed the relay enforced its own least-privilege roles.
Compensating Controls
Treat the web management interface as untrusted until the device is running a fixed firmware version. Do not rely on active vulnerability scanning to confirm exposure, since aggressive probing of protection relays can lock accounts, exhaust sessions, or in some cases disrupt device processing. Enumerate affected assets from passive traffic capture and configuration inventory instead.
- Isolate the management plane. Restrict the web interface to a dedicated engineering VLAN reachable only from hardened jump hosts. Block relay HTTP and HTTPS management ports from general operator and corporate segments at the firewall.
- Rotate and tier credentials. Eliminate shared low-privilege accounts, since this exploit requires a valid authenticated session. Removing casual login access removes the launch point.
- Virtual patch at the conduit. Where a proxy or inline IPS fronts the management interface, enforce that only known-good administrative requests originate from authorized engineering hosts, and drop privileged endpoint access from operator-tier sessions.
- Suricata rule concept. Alert on HTTP POST or PUT requests to relay configuration and account endpoints where the source address is outside the engineering host allowlist, and flag anomalous parameter fields that indicate role or resource manipulation. Tune against a baseline of legitimate engineering activity to avoid false positives during commissioning windows.
- Session monitoring. Log and review privileged configuration changes with timestamps and source identity so an escalation attempt surfaces even if the request itself is not blocked.
Confirm the fixed firmware level directly with the vendor advisory before planning any relay firmware upgrade, and schedule it within a controlled maintenance outage rather than online.
BreachSpider Intel
BreachSpider tracks CVE-2026-62650 and related protection relay authorization defects across our OT vulnerability intelligence so operators can monitor exposure and validate compensating controls in real time.