Siemens SIMOVE Fleetmanager and SIPLANT
Summary
Siemens SIMOVE Fleetmanager and SIPLANT products are affected by a path traversal vulnerability (CVE-2026-67367) that allows unauthenticated remote attackers to read arbitrary files from the operating system. Siemens has released updated versions to address this critical flaw.
IFF Assessment
FOE
The identified vulnerability allows remote attackers to access sensitive files, posing a significant risk to data security and system integrity.
Severity
8.6
High
Defender Context
This vulnerability in Siemens industrial control system (ICS) products highlights the ongoing risk of path traversal attacks in operational technology (OT) environments. Defenders should prioritize patching these systems and implementing network segmentation to limit the impact of any successful exploit.