IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT

HIGH
CVSS 8.6
Date 2026-09-08T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-67367 8.6 high
CVE-2026-67367. Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.

// Remediations (8)

Mitigation: Configure appropriate user management by restricting services' access rights to project files
Configure appropriate user management by restricting services' access rights to project files
Patch: Update to V3.1.4 or later version Contact customer support [email protected]
Update to V3.1.4 or later version Contact customer support [email protected]
Patch: Update to V4.0.1 or later version
Update to V4.0.1 or later version
Patch: Update to V3.2.4 or later version
Update to V3.2.4 or later version
Patch: Update to V3.1.13 or later version
Update to V3.1.13 or later version
Mitigation: Restrict network access to affected devices
Restrict network access to affected devices
Patch: Update to V3.3.2 or later version
Update to V3.3.2 or later version
Patch: Contact customer support [email protected]
Contact customer support [email protected]

// References