Executive Summary
CVE-2026-62647 stems from a random number generator in the Reyrolle 7SR5 protection relay that generates security-relevant values, including session identifiers, without being seeded from a True Random Number Generator (TRNG), producing a predictable sequence. An unauthenticated remote attacker who can predict these values can impersonate a legitimate authenticated user and gain unauthorized access to a device that directly controls protection and tripping logic on distribution and transmission feeders.
Technical Exposure Breakdown
The affected component is the session authentication layer of the Reyrolle 7SR5 relay across all versions before V2.70, per the grounding data. The defect is not in the authentication credential itself but in the entropy source that backs session identifier generation. When a session token generator is initialized from a deterministic or low-entropy seed rather than a hardware TRNG, the output sequence becomes reproducible. An attacker who observes or brute forces a small window of prior values can compute subsequent tokens.
The attack vector is network reachable and requires no prior authentication. Assigned a CVSS score of 7.4, the flaw does not demand physical access or valid credentials. Practical exploitation depends on the attacker having a path to the relay management interface. In a correctly segmented substation, that path should not exist from outside the process and control zones. In practice, engineering access networks, flat station LANs, and remote vendor connectivity frequently collapse that separation. Session prediction is quiet. There is no failed login pattern, no lockout, and no credential compromise event for a SIEM to catch, because the attacker rides a valid session identifier that the relay itself considers legitimate.
OT Impact and Compliance Risk
A protection relay is not a data device. It decides when to open a breaker. Unauthorized authenticated access can allow modification of protection settings, pickup thresholds, trip curves, and communication parameters. Altered settings can cause a relay to fail to trip on a genuine fault, or to trip spuriously and drop load. Either outcome carries physical consequences ranging from equipment damage to cascading feeder outages. The compromise of the authentication boundary means an operator can no longer trust that a session came from an authorized engineer.
For NERC CIP entities, this affects CIP-005 electronic access controls and CIP-007 system security management, because the predictable session mechanism undermines the access control assumptions of the relay itself. Under IEC 62443, this is a failure of foundational requirement FR1, identification and authentication control, and it degrades the effective security level of any zone containing the device. Utilities running these relays in bulk electric system applications should treat the affected zone as having a reduced trust boundary until remediated.
Compensating Controls
Do not attempt to validate exposure with active scanning against the relay management interface. Protection relays are sensitive to unexpected traffic, and aggressive probing can degrade or crash the device, which on a protection asset is a safety event, not an inconvenience. Use passive traffic analysis and configuration review instead.
- Isolate the management plane. Restrict the relay authentication interface to a dedicated engineering VLAN reachable only from a hardened jump host. If remote vendor access exists, terminate it and re-establish it through a brokered, logged, and time-bounded session.
- Enforce network layer authentication. Because the device-level session control cannot be trusted, place the trust boundary at the network. Firewall rules and access control lists should permit management traffic only from known engineering source addresses.
- Virtual patch at the perimeter. Deploy inspection at the zone conduit to flag session establishment from unexpected sources. A Suricata rule concept: alert on connections to the relay management port originating from any address outside the approved engineering allowlist, and separately alert on rapid sequential session establishment attempts that suggest token enumeration. This does not fix the entropy defect, but it constrains the reachable attack surface and creates detection where none exists at the device.
- Session hygiene. Terminate idle engineering sessions promptly to shrink the prediction window an attacker can exploit.
Track the vendor fixed version through your asset management process and schedule remediation within a controlled outage window rather than assuming a live update is safe on a protection asset.
BreachSpider Intel
BreachSpider tracks CVE-2026-62647 and related protection relay exposures across the OT vulnerability landscape for continuous monitoring and prioritization.