Skip to content

Security1 publisher2 min readPublished

CVE-2026-67367 lets an unauthenticated request read private keys off SIMOVE Fleetmanager hosts

Siemens ProductCERT reported the traversal itself, and fixed builds are out for four SIMOVE Fleetmanager branches and SIPLANT V3.1. For SIPLANT V1.7, V2.2 and V3.0 the advisory's remedy is an email to support.

The Watch · Security desk

Photograph accompanying CVE-2026-67367 lets an unauthenticated request read private keys off SIMOVE Fleetmanager hosts
Photo: siemens.com

What happened

  • The file-serving endpoint of the embedded HTTP server in SIMOVE Fleetmanager and SIPLANT does not neutralize directory traversal sequences, so an unauthenticated remote attacker can read arbitrary files from the operating system.
  • CISA lists eight affected version lines under CVE-2026-67367, four SIMOVE Fleetmanager branches and four SIPLANT branches, in products Siemens sells into critical manufacturing worldwide.
  • Fixed builds are SIMOVE Fleetmanager V3.1.13, V3.2.4, V3.3.2 and V4.0.1, plus SIPLANT V3.1.4, which is obtained through Siemens customer support.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Anything the HTTP server process can open is reachable from the network without a credential, so a fleet management host becomes a place to collect keys for use against the systems it manages.
  • decision Owners of SIPLANT V1.7, V2.2 or V3.0 have to treat network isolation as the control of record while a support ticket runs, because there is no version number to schedule an upgrade against.
  • constraint SIMOVE sites can pull builds from Siemens' support pages on their own schedule; SIPLANT sites cannot, because every SIPLANT fix in this advisory is gated on a reply from one support mailbox.
  • capability This buys an attacker file reads and nothing more, which puts it in the reconnaissance and credential-theft column rather than the remote-execution one.

Traversal on a file-serving endpoint gives an attacker whatever the serving process can open. Siemens' first mitigation goes to that boundary: configure user management so that services' access rights to project files are restricted [8]. On a host where the embedded HTTP server runs with broad rights, the reachable set includes the credential stores, private keys and configuration secrets CISA names [2]. No login sits in front of the endpoint, and the request needs no credentials [2]. CISA classes the defect as CWE-23, relative path traversal [3].

Eight version lines are listed as affected [4]. Five of them have a build to move to: SIMOVE Fleetmanager V3.1.13, V3.2.4, V3.3.2 and V4.0.1, plus SIPLANT V3.1.4 [5]. The remaining three are SIPLANT V1.7, V2.2 and V3.0, each listed as affected at all versions, and the remediation Siemens gives for them is to contact customer support at [email protected] [6][13].

The SIMOVE updates sit on Siemens' industry support site, with V4.0.1 on a separate page from the V3.x builds [7]. Every SIPLANT remediation in the advisory routes through the one support mailbox, including the V3.1.4 upgrade [6][5]. Four SIMOVE branches are affected at once, so an operator running mixed sites may need up to four distinct target builds off a single advisory [14].

Siemens ProductCERT reported the vulnerability to CISA, and the advisory does not report exploitation [10]. That is the ordinary vendor-discovered path. It also means the defect is now described publicly in enough detail to write a request against: an unvalidated traversal sequence in a file-serving endpoint is portable across all eight listed lines [2][4].

Read-only file disclosure is the whole of it. There is no code execution claimed here [1]. The value to an attacker is the second step: keys and configuration secrets lifted off a fleet management host get used against the systems that host talks to [2]. Siemens deploys these products worldwide into critical manufacturing [9].

For the three SIPLANT lines without a build, the interim control is the network. Siemens' second mitigation is to restrict network access to affected devices [8], and CISA's standing guidance is to keep control system devices off the internet, behind firewalls, isolated from business networks, with VPN where remote access is required [11]. Siemens tracks the issue as SSA-517424 [12].

What to watch

  • Whether Siemens publishes fixed builds for SIPLANT V1.7, V2.2 and V3.0 or declares those lines out of support.
  • Whether a working request for CVE-2026-67367 is published; one traversal string would cover all eight affected lines.
  • Whether scan data turns up internet-facing SIMOVE Fleetmanager HTTP endpoints, which CISA's guidance assumes do not exist.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories