Siemens SIMOVE Fleetmanager and SIPLANT

Summary

Siemens SIMOVE Fleetmanager and SIPLANT products are affected by a path traversal vulnerability (CVE-2026-67367) that allows unauthenticated remote attackers to read arbitrary files from the operating system. Siemens has released updated versions to address this critical flaw.

IFF Assessment

FOE

The identified vulnerability allows remote attackers to access sensitive files, posing a significant risk to data security and system integrity.

Severity

8.6 High

Defender Context

This vulnerability in Siemens industrial control system (ICS) products highlights the ongoing risk of path traversal attacks in operational technology (OT) environments. Defenders should prioritize patching these systems and implementing network segmentation to limit the impact of any successful exploit.

Read Full Story →