Siemens SIMOVE Fleetmanager: path traversal
Critical9.2CVE-2026-67367 · Published Sep 8, 2026 · updated Sep 9, 2026
A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SIMOVE Fleetmanager V3.1 Product | < V3.1.13 | V3.1.13 |
| SIMOVE Fleetmanager V3.2 Product | < V3.2.4 | V3.2.4 |
| SIMOVE Fleetmanager V3.3 Product | < V3.3.2 | V3.3.2 |
| SIMOVE Fleetmanager V4.0 Product | < V4.0.1 | V4.0.1 |
| SIPLANT V1.7 Product | all versions | No fix yet |
| SIPLANT V2.2 Product | all versions | No fix yet |
| SIPLANT V3.0 Product | all versions | No fix yet |
| SIPLANT V3.1 Product | < V3.1.4 | V3.1.4 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-23
More Siemens advisories
All Siemens| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Siemens Reyrolle 7SR5: denial of service | High8.7 | V2.70 |
| Sep 8 | Siemens Reyrolle 7SR5: improper access control | High8.7 | V2.70 |
| Sep 8 | Siemens Reyrolle 7SR5: unauthenticated attacker could the publicly available | Medium6.9 | V2.70 |
| Sep 8 | Siemens Reyrolle 7SR5: memory corruption | High7.0 | V2.70 |
| Sep 8 | Siemens Reyrolle 7SR5: attacker could the device to upload | High7.0 | V2.70 |
| Sep 8 | Siemens Teamcenter: cross-site scripting | High8.5 | V2412.0013+3 more |