CVE-2026-67367
nicheUnauthenticated Directory Traversal File Read in Siemens SIMOVE Fleetmanager and SIPLANT
Siemens SIMOVE Fleetmanager and SIPLANT contain a directory traversal flaw (CWE-23) in the file-serving endpoint of an embedded HTTP server, which fails to validate and neutralize traversal sequences. An unauthenticated remote attacker can send crafted requests containing directory traversal sequences to this endpoint and read arbitrary files from the underlying operating system with no credentials required. Successful exploitation can expose sensitive data such as credential stores, private keys, and configuration secrets, potentially enabling follow-on compromise of the deployment. Affected users are operators running the listed SIMOVE Fleetmanager releases (V3.1 through V4.0 below the fixed versions) and any release of SIPLANT V1.7, V2.2, V3.0, or V3.1 below V3.1.4. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at only 0.8%, so no exploitation is currently known.
What to do: Upgrade SIMOVE Fleetmanager to V3.1.13, V3.2.4, V3.3.2, or V4.0.1 or later depending on your release line, and upgrade SIPLANT to V3.1.4 or later; SIPLANT V1.7, V2.2, and V3.0 have no listed fixed version, so check the Siemens ProductCERT advisory for update or migration options. Restrict network access to the embedded HTTP server (e.g., firewall rules or network segmentation) until patched. Because the flaw allows reading credential stores and private keys, review whether sensitive files were reachable on any exposed instance and rotate secrets if compromise is suspected.
| Siemens SIMOVE Fleetmanager | V3.1, all versions < V3.1.13 |
| Siemens SIMOVE Fleetmanager | V3.2, all versions < V3.2.4 |
| Siemens SIMOVE Fleetmanager | V3.3, all versions < V3.3.2 |
| Siemens SIMOVE Fleetmanager | V4.0, all versions < V4.0.1 |
| Siemens SIPLANT | V1.7, all versions |
| Siemens SIPLANT | V2.2, all versions |
| Siemens SIPLANT | V3.0, all versions |
| Siemens SIPLANT | V3.1, all versions < V3.1.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.
- Weakness
- CWE-23
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.