Skip to content
Security & Trust

Siemens SIMOVE and SIPLANT flaw could expose system files without a login

CISA republished Siemens' advisory on a path traversal in the products' embedded web server. Five version lines are affected.

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
Siemens SIMOVE and SIPLANT flaw could expose system files without a login

AI-generated image for WebPulse. About our images

Key finding

Affected version lines: 5 (Source: CISA ICS advisory ICSA-26-265-07, republishing Siemens ProductCERT SSA-517424 (September 22, 2026))

On September 22, 2026, CISA republished Siemens ProductCERT advisory SSA-517424, which covers a path traversal vulnerability, CVE-2026-67367, in SIMOVE Fleetmanager and SIPLANT. According to the advisory, the part of the products' built-in web server that serves files fails to screen out directory traversal sequences. As a result, someone who can reach an affected device over the network, and who holds no account or password, could read files from the device's underlying operating system. The advisory tags the affected sector as Critical Manufacturing.

5
Affected version lines
Source: CISA ICS advisory ICSA-26-265-07, republishing Siemens ProductCERT SSA-517424 (September 22, 2026)

The files that could be read include credentials, private keys and configuration secrets

A file-read flaw can sound minor next to remote code execution. The advisory's own examples suggest otherwise: it names credential stores, private keys and configuration secrets as data that could be exposed. Files of this kind can matter beyond the device that holds them. What an attacker could do with them is a question for your own team, because the advisory does not describe downstream use. It also does not say whether the flaw has been exploited.

That changes what patching means. Updating to a fixed version addresses the flaw going forward, but it does not tell you whether anything was read beforehand. Organisations that ran an affected version on a reachable network should treat secret rotation as a separate decision from the patch.

Which versions are affected, and what fixes them

The advisory lists four SIMOVE Fleetmanager lines and one SIPLANT line as affected. Fleetmanager V3.1 is affected below 3.1.13, V3.2 below 3.2.4, V3.3 below 3.3.2 and V4.0 below 4.0.1. SIPLANT V3.1 is affected below 3.1.4. Siemens' fix links for Fleetmanager point to its support portal, and SIPLANT fixes run through a support contact. The advisory also includes a vendor-fix entry that says only to contact customer support, with no version attached, so confirm the exact target release with Siemens.

3.1.13
Fleetmanager V3.1 fixed release
Source: CISA ICS advisory ICSA-26-265-07, republishing Siemens SSA-517424 (September 22, 2026)
3.1.4
SIPLANT V3.1 fixed release
Source: CISA ICS advisory ICSA-26-265-07, republishing Siemens SSA-517424 (September 22, 2026)

Mitigation rests on network exposure

Where patching has to wait, Siemens advises limiting who can reach the affected devices and tightening user management so that services have narrower rights over project files. CISA's wider guidance for control systems is architectural: keep such equipment unreachable from the internet, and use firewalls to separate the control network from corporate IT. Where remote access is unavoidable, it suggests VPNs, while cautioning that a VPN inherits the weaknesses of whatever connects through it.

One caveat on sourcing: CISA describes this as a verbatim republication of Siemens' advisory and states it is not responsible for the advisory's technical accuracy. Siemens ProductCERT is the authoritative reference for version and fix details.

Questions to put to your team

1. Do we run SIMOVE Fleetmanager or SIPLANT anywhere, and on which version lines? Does the inventory show the version, or only that the product exists?

2. Can the embedded web server on any of these devices be reached from a business network, a vendor connection or the internet?

3. For any device that was reachable while unpatched, which credentials, keys and configuration secrets sit on it, and can we rotate them without disrupting production?

4. Who owns the update, and has the impact analysis CISA asks for before deploying defensive measures been done? If the window is weeks away, is network restriction in place until then?

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.

CVEs in this analysis
CVE-2026-67367
Share this insight