Skip to content
SiemensCVE-2026-67367

Siemens SIMOVE Fleetmanager: path traversal

Critical9.2CVE-2026-67367 · Published Sep 8, 2026 · updated Sep 9, 2026

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.

Siemens advisory

Affected versions

PackageAffectedFixed in
SIMOVE Fleetmanager V3.1
Product
< V3.1.13V3.1.13
SIMOVE Fleetmanager V3.2
Product
< V3.2.4V3.2.4
SIMOVE Fleetmanager V3.3
Product
< V3.3.2V3.3.2
SIMOVE Fleetmanager V4.0
Product
< V4.0.1V4.0.1
SIPLANT V1.7
Product
all versionsNo fix yet
SIPLANT V2.2
Product
all versionsNo fix yet
SIPLANT V3.0
Product
all versionsNo fix yet
SIPLANT V3.1
Product
< V3.1.4V3.1.4
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-23

More Siemens advisories

All Siemens
Advisory
Siemens Reyrolle 7SR5: denial of service
High8.7Sep 8
Siemens Reyrolle 7SR5: improper access control
High8.7Sep 8
Siemens Reyrolle 7SR5: unauthenticated attacker could the publicly available
Medium6.9Sep 8
Siemens Reyrolle 7SR5: memory corruption
High7.0Sep 8
Siemens Reyrolle 7SR5: attacker could the device to upload
High7.0Sep 8
Siemens Teamcenter: cross-site scripting
High8.5Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.