Directory Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT Products
CVE-2026-67367
9.2CRITICAL
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-67367?
A security issue has been discovered in the SIMOVE Fleetmanager versions prior to V3.1.13, V3.2.4, V3.3.2, and V4.0.1, as well as in all versions of SIPLANT. The vulnerability arises from improper validation and neutralization of directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This flaw could enable an unauthenticated remote attacker to read arbitrary files from the underlying operating system, potentially exposing sensitive information such as credential stores, private keys, and configuration secrets.
Affected Version(s)
SIMOVE Fleetmanager V3.1 0
SIMOVE Fleetmanager V3.2 0
SIMOVE Fleetmanager V3.3 0