ZeroHour

CVE-2026-67367

niche

Unauthenticated Directory Traversal File Read in Siemens SIMOVE Fleetmanager and SIPLANT

CVSS 4.0
9.2 critical
EPSS
<1%p55
Published
()
Modified
AI analysis

Siemens SIMOVE Fleetmanager and SIPLANT contain a directory traversal flaw (CWE-23) in the file-serving endpoint of an embedded HTTP server, which fails to validate and neutralize traversal sequences. An unauthenticated remote attacker can send crafted requests containing directory traversal sequences to this endpoint and read arbitrary files from the underlying operating system with no credentials required. Successful exploitation can expose sensitive data such as credential stores, private keys, and configuration secrets, potentially enabling follow-on compromise of the deployment. Affected users are operators running the listed SIMOVE Fleetmanager releases (V3.1 through V4.0 below the fixed versions) and any release of SIPLANT V1.7, V2.2, V3.0, or V3.1 below V3.1.4. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at only 0.8%, so no exploitation is currently known.

What to do: Upgrade SIMOVE Fleetmanager to V3.1.13, V3.2.4, V3.3.2, or V4.0.1 or later depending on your release line, and upgrade SIPLANT to V3.1.4 or later; SIPLANT V1.7, V2.2, and V3.0 have no listed fixed version, so check the Siemens ProductCERT advisory for update or migration options. Restrict network access to the embedded HTTP server (e.g., firewall rules or network segmentation) until patched. Because the flaw allows reading credential stores and private keys, review whether sensitive files were reachable on any exposed instance and rotate secrets if compromise is suspected.

Affected
Siemens SIMOVE FleetmanagerV3.1, all versions < V3.1.13
Siemens SIMOVE FleetmanagerV3.2, all versions < V3.2.4
Siemens SIMOVE FleetmanagerV3.3, all versions < V3.3.2
Siemens SIMOVE FleetmanagerV4.0, all versions < V4.0.1
Siemens SIPLANTV1.7, all versions
Siemens SIPLANTV2.2, all versions
Siemens SIPLANTV3.0, all versions
Siemens SIPLANTV3.1, all versions < V3.1.4
Estimated exposure
nichelikely hundreds to low thousands of installations worldwide — These are specialized Siemens industrial software products deployed as dedicated server instances at industrial and logistics sites, a customer base that plausibly numbers on the order of a thousand sites globally rather than a mass-market…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.

Weakness
CWE-23
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.