Executive Summary

CVE-2026-62647 stems from a random number generator in the Reyrolle 7SR5 protection relay that generates security-relevant values, including session identifiers, without being seeded from a True Random Number Generator (TRNG), producing a predictable sequence. An unauthenticated remote attacker who can predict these values can impersonate a legitimate authenticated user and gain unauthorized access to a device that directly controls protection and tripping logic on distribution and transmission feeders.

Technical Exposure Breakdown

The affected component is the session authentication layer of the Reyrolle 7SR5 relay across all versions before V2.70, per the grounding data. The defect is not in the authentication credential itself but in the entropy source that backs session identifier generation. When a session token generator is initialized from a deterministic or low-entropy seed rather than a hardware TRNG, the output sequence becomes reproducible. An attacker who observes or brute forces a small window of prior values can compute subsequent tokens.

The attack vector is network reachable and requires no prior authentication. Assigned a CVSS score of 7.4, the flaw does not demand physical access or valid credentials. Practical exploitation depends on the attacker having a path to the relay management interface. In a correctly segmented substation, that path should not exist from outside the process and control zones. In practice, engineering access networks, flat station LANs, and remote vendor connectivity frequently collapse that separation. Session prediction is quiet. There is no failed login pattern, no lockout, and no credential compromise event for a SIEM to catch, because the attacker rides a valid session identifier that the relay itself considers legitimate.

OT Impact and Compliance Risk

A protection relay is not a data device. It decides when to open a breaker. Unauthorized authenticated access can allow modification of protection settings, pickup thresholds, trip curves, and communication parameters. Altered settings can cause a relay to fail to trip on a genuine fault, or to trip spuriously and drop load. Either outcome carries physical consequences ranging from equipment damage to cascading feeder outages. The compromise of the authentication boundary means an operator can no longer trust that a session came from an authorized engineer.

For NERC CIP entities, this affects CIP-005 electronic access controls and CIP-007 system security management, because the predictable session mechanism undermines the access control assumptions of the relay itself. Under IEC 62443, this is a failure of foundational requirement FR1, identification and authentication control, and it degrades the effective security level of any zone containing the device. Utilities running these relays in bulk electric system applications should treat the affected zone as having a reduced trust boundary until remediated.

Compensating Controls

Do not attempt to validate exposure with active scanning against the relay management interface. Protection relays are sensitive to unexpected traffic, and aggressive probing can degrade or crash the device, which on a protection asset is a safety event, not an inconvenience. Use passive traffic analysis and configuration review instead.

Track the vendor fixed version through your asset management process and schedule remediation within a controlled outage window rather than assuming a live update is safe on a protection asset.

BreachSpider Intel

BreachSpider tracks CVE-2026-62647 and related protection relay exposures across the OT vulnerability landscape for continuous monitoring and prioritization.