CVE-2026-67367
8.6Siemens · SIMOVE Fleetmanager, SIPLANT
A directory traversal vulnerability in the embedded HTTP server of Siemens SIMOVE Fleetmanager and SIPLANT allows unauthenticated remote attackers to read arbitrary files from the host system.
Executive summary
An unauthenticated directory traversal vulnerability in Siemens SIMOVE Fleetmanager and SIPLANT allows remote attackers to access sensitive system files, posing a high risk to infrastructure security.
Vulnerability
The vulnerability is caused by improper neutralization of directory traversal sequences within the file-serving endpoint of the embedded HTTP server. This flaw allows an unauthenticated remote attacker to bypass access controls and read arbitrary files from the underlying operating system.
Business impact
Successful exploitation of this vulnerability could lead to the unauthorized disclosure of highly sensitive information, including credential stores, private cryptographic keys, and system configuration secrets. Given the CVSS score of 8.6, this represents a significant security risk that could facilitate lateral movement, credential theft, and total compromise of the affected industrial management systems.
Remediation
Immediate Action: Update SIMOVE Fleetmanager to the specified fixed versions (V3.1.13, V3.2.4, V3.3.2, or V4.0.1) or SIPLANT to V3.1.4 immediately. For versions where a patch is not yet available, restrict network access to the affected devices.
Proactive Monitoring: Monitor network traffic for anomalous HTTP requests containing directory traversal patterns such as "../" or ".." directed at the web interface.
Compensating Controls: Implement Web Application Firewall (WAF) rules to inspect incoming traffic and block requests containing path traversal sequences directed at the Siemens management interfaces.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high CVSS score reflects the severity of allowing unauthenticated access to system-level files on industrial management software. Administrators should prioritize patching the identified SIMOVE Fleetmanager versions and monitor vendor portals for impending updates for the remaining SIPLANT versions to mitigate this critical exposure.
More Siemens CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section