CVE-2026-67367 Details
Description
A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.
A path traversal vulnerability has been identified in multiple versions of Siemens SIMOVE Fleetmanager (V3.1 prior to V3.1.13, V3.2 prior to V3.2.4, V3.3 prior to V3.3.2, and V4.0 prior to V4.0.1) and SIPLANT (V1.7, V2.2, V3.0, and V3.1 prior to V3.1.4). The vulnerability arises because affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This flaw could enable an unauthenticated remote attacker to read arbitrary files from the underlying operating system, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.
Siemens has released new versions for the affected products. For SIMOVE Fleetmanager, users should update to the latest version. For SIPLANT, users should also update to the latest version. Additionally, Siemens recommends restricting network access to affected devices and configuring user management to limit access rights to project files.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-517424.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens SIMOVE Fleetmanager | < V3.1.13 < V3.2.4 < V3.3.2 < V4.0.1 |
CPE
Remediation
| |
| Siemens SIPLANT | < V1.7 < V2.2 < V3.0 < V3.1.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion