Machine-generated analysis · WAYSCloud LLM
Siemens SIMOVE Fleetmanager and SIPLANT are vulnerable to a relative path-traversal flaw (CVE-2026-67367). Siemens has published newer versions and advises updating to the latest releases.
Context
The advisory covers Siemens SIMOVE Fleetmanager (versions V3.1-V4.0) and SIPLANT (versions V1.7-V3.1). The affected versions allow an unauthenticated remote attacker to read arbitrary files via directory traversal in the embedded HTTP server, potentially exposing credential stores, private keys, and configuration secrets. The products are deployed worldwide in the critical manufacturing sector and have a CVSS v3 score of 8.6.
Operator considerations
- Check: Verify the installed SIMOVE Fleetmanager and SIPLANT versions against the affected list.
- Isolate: Restrict network access to the HTTP file-serving endpoint until the update is applied.
- Patch: Install the latest Siemens releases for the affected products as recommended.
- Log: Watch HTTP request logs for directory-traversal patterns such as "../" and unexpected file access.
SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens SIMOVE Fleetmanager and SIPLANT are affected:
SIMOVE Fleetmanager V3.1 vers:intdot/
Read the full advisory on CISA →