Siemens fleet management tools hit by unauthenticated file-read flaw
CVE-2026-67367 lets unauthenticated attackers read arbitrary files from the underlying OS (credential stores, private keys, configuration secrets) without any credentials.
TL;DR
Siemens released patches for a path traversal vulnerability (CVE-2026-67367, CVSS 8.6) in SIMOVE Fleetmanager and SIPLANT that allows unauthenticated remote attackers to read arbitrary files from the embedded HTTP server's host operating system. Affected versions span SIMOVE Fleetmanager V3.1 through V4.0 and SIPLANT V1.7 through V3.1. Fleetmanager fixes are available through Siemens' support portal. For SIPLANT V1.7 and V2.2 (all versions affected) Siemens directs users to contact customer support rather than pointing to a published patch. SIPLANT V3.0 is also affected across all versions with no patch version specified.
Siemens disclosed CVE-2026-67367, a path traversal vulnerability in the file-serving endpoint of the embedded HTTP server used by SIMOVE Fleetmanager and SIPLANT. The flaw allows an unauthenticated remote attacker to read arbitrary files from the underlying operating system without credentials.
The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N) tells a specific story: network-reachable, low complexity, no privileges, no user interaction, and a changed scope that moves the confidentiality impact to the host OS. What an attacker reads depends on what the deployment stores on disk, but the CISA advisory flags credential stores, private keys, and configuration secrets as the exposure surface.
Who needs to move
SIMOVE Fleetmanager V3.1 before V3.1.13, V3.2 before V3.2.4, V3.3 before V3.3.2, and V4.0 before V4.0.1 are affected. Patch downloads are available through Siemens' support portal for each branch.
SIPLANT presents a rougher path. V3.1 requires an update to V3.1.4 or later. V1.7 and V2.2 are affected across all versions, and Siemens' remediation mapping directs users to contact siplant-support.de@siemens.com rather than linking to a published fix. V3.0 is also listed as all versions affected, with the remediation table pointing to the same customer-support contact, no fixed version is specified. That means operators running three of the four SIPLANT version lines don't have a downloadable patch today.
Mitigations are not closure
Siemens' advisory recommends restricting network access to affected devices and configuring user management to limit service access rights to project files. Those are network-architecture mitigations, not configuration toggles within the product. For facilities where SIMOVE and SIPLANT are integrated into production network segments, segmenting them off means downtime windows that compete with operational schedules.
CISA's republication of the advisory identifies critical manufacturing as the affected sector and worldwide deployment. The agency's standard ICS guidance applies: minimize network exposure, isolate control system networks behind firewalls, and use VPNs where remote access is required.
For Fleetmanager users, the patch is the exit. For SIPLANT shops on V1.7, V2.2, or V3.0, the near-term plan is network isolation and an email to Siemens, with no published timeline for when a downloadable fix replaces the contact-support instruction.
Published ·Deep Fathom