VYPR
advisoryPublished Sep 22, 2026· 1 source

Critical Path Traversal Vulnerability in Siemens SIMOVE Fleetmanager and SIPLANT Exposes Sensitive Files

Siemens SIMOVE Fleetmanager and SIPLANT products are affected by a critical path traversal vulnerability, CVE-2026-67367, allowing unauthenticated attackers to read arbitrary files.

Siemens has issued a security advisory detailing a critical path traversal vulnerability affecting its SIMOVE Fleetmanager and SIPLANT industrial control system products. The flaw, identified as CVE-2026-67367, resides within the embedded HTTP server and could permit unauthenticated remote attackers to access sensitive files on the underlying operating system.

The vulnerability stems from improper validation and neutralization of directory traversal sequences within the file-serving endpoint. This allows an attacker to navigate beyond the intended directory structure and read arbitrary files. The potential impact includes the exposure of critical data such as credential stores, private keys, and configuration secrets, which could be leveraged for further system compromise.

Several versions of SIMOVE Fleetmanager are affected, including V3.1 prior to V3.1.13, V3.2 prior to V3.2.4, V3.3 prior to V3.3.2, and V4.0 prior to V4.0.1. For SIPLANT, all versions of V1.7, V2.2, and V3.0 are vulnerable, along with V3.1 prior to V3.1.4.

The Common Vulnerability Scoring System (CVSS) v3.1 base score for this vulnerability is a high 8.6, categorized as HIGH severity. The vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N highlights its network accessibility, low attack complexity, lack of required privileges or user interaction, and its potential to impact confidentiality significantly.

Siemens has released updated versions to address this vulnerability. Users are strongly advised to update SIMOVE Fleetmanager to V3.1.13 or later, V3.2.4 or later, V3.3.2 or later, or V4.0.1 or later. For SIPLANT, users should update to V3.1.4 or later, or contact customer support for other versions. Mitigation strategies also include restricting network access to affected devices and configuring appropriate user management to limit services' access rights to project files.

CISA recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating them behind firewalls, isolated from business networks. Secure remote access methods like VPNs should be used when necessary, ensuring they are also kept up-to-date.

This advisory was reported to CISA by ProductCERT and is a direct republication of Siemens' own security advisory SSA-517424. Organizations are encouraged to follow Siemens' operational guidelines for Industrial Security and consult their product manuals for further hardening recommendations.

The widespread deployment of Siemens products across critical manufacturing sectors globally underscores the importance of promptly addressing this vulnerability to prevent potential disruptions and data breaches.

Synthesized by Vypr AI