security1 publisher
Siemens Reyrolle 7SR5 relays generate session tokens an unauthenticated attacker can compute
Siemens has released V2.70 for the Reyrolle 7SR5 protection relay. The CISA advisory behind it describes a session identifier an unauthenticated remote attacker can derive, plus five memory bugs in an embedded third-party web server.
Publishers:cisa.gov
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives45
- Confidence72