๐Ÿ” CVE Alert

CVE-2026-67367

HIGH 8.6
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.

CWE CWE-23
Vendor siemens
Product simove fleetmanager v3.1
Ecosystems
Industries
IndustrialManufacturing
Published Sep 8, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for siemens simove fleetmanager v3.1

Be the first to know when new high vulnerabilities affecting siemens simove fleetmanager v3.1 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Siemens / SIMOVE Fleetmanager V3.1
0 < V3.1.13
Siemens / SIMOVE Fleetmanager V3.2
0 < V3.2.4
Siemens / SIMOVE Fleetmanager V3.3
0 < V3.3.2
Siemens / SIMOVE Fleetmanager V4.0
0 < V4.0.1
Siemens / SIPLANT V1.7
0 < *
Siemens / SIPLANT V2.2
0 < *
Siemens / SIPLANT V3.0
0 < *
Siemens / SIPLANT V3.1
0 < V3.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cert-portal.siemens.com: https://cert-portal.siemens.com/productcert/html/ssa-517424.html