← All Advisories

CVE-2026-67367

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-67367

Key Details

CVECVE-2026-67367
CVSS Score / Version8.6 (High) / CVSS v3.1
Updated2026-09-09
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productssee table below
Classified asCWE-23 (Relative Path Traversal)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SiemensSIMOVE Fleetmanager V3.1
SiemensSIMOVE Fleetmanager V3.2
SiemensSIMOVE Fleetmanager V3.3
SiemensSIMOVE Fleetmanager V4.0
SiemensSIPLANT V1.7
SiemensSIPLANT V2.2
SiemensSIPLANT V3.0
SiemensSIPLANT V3.1
SubsystemsGeneral OT
SectorsMultiple

What to Know

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-67367
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-67367