VORANT. Threat Intelligence Sign in Get the full feed

Siemens SIMOVE/SIPLANT path traversal flaw patched

routine vulnerability manufacturing

An unauthenticated path traversal bug in Siemens SIMOVE Fleetmanager and SIPLANT lets remote attackers read arbitrary files including credentials and secrets; patches available.

Siemens has disclosed CVE-2026-67367, a directory traversal vulnerability (CWE-23) affecting the embedded HTTP server's file-serving endpoint in SIMOVE Fleetmanager and SIPLANT products. The flaw stems from improper validation of directory traversal sequences, allowing an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials. This could expose sensitive data such as credential stores, private keys, and configuration secrets.

Affected products span multiple version lines: SIMOVE Fleetmanager V3.1 (<3.1.13), V3.2 (<3.2.4), V3.3 (<3.3.2), V4.0 (<4.0.1), and SIPLANT V1.7, V2.2, V3.0 (all versions), and V3.1 (<3.1.4). Siemens has released fixed versions for most affected lines; SIPLANT V1.7, V2.2, and V3.0 have no vendor fix and require contacting Siemens customer support directly. There is no indication of active exploitation in the wild; this is a vendor-disclosed advisory republished by CISA.

Defenders operating these products in industrial/manufacturing environments should prioritize updating to the fixed versions where available, restrict network access to the affected HTTP servers, and follow standard ICS network segmentation practices (isolating control system networks behind firewalls, avoiding direct internet exposure, and using VPNs for remote access). Given the unauthenticated nature of the flaw and potential for credential/secret exposure, organizations should treat exposed instances as a priority for remediation even absent confirmed in-the-wild exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-67367

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-07

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free