Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT

Plan PatchCVSS 8.6SSA-517424Sep 8, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability (CWE-23) that allows an attacker with network access to read files outside of the intended application scope. An attacker could access sensitive project files, configuration data, or other files on the affected device without authentication.

What this means
What could happen
An attacker could access sensitive project files, configurations, and control system data on SIMOVE Fleetmanager or SIPLANT systems without credentials, potentially exposing process parameters, credentials, or other sensitive operational information.
Who's at risk
This affects organizations using SIMOVE Fleetmanager (versions 3.1, 3.2, 3.3, or 4.0) or SIPLANT (versions 1.7, 2.2, 3.0, or 3.1) for fleet management or plant operations data management. Information disclosure risk is highest if these systems are accessible from your corporate network or connected to process networks.
How it could be exploited
An attacker with network access to the SIMOVE Fleetmanager or SIPLANT web interface crafts a specially-formed request using path traversal techniques (e.g., "../" sequences) to access files outside the intended application directory. The vulnerability requires no authentication, allowing the attacker to read arbitrary files on the server.
Prerequisites
  • Network access to SIMOVE Fleetmanager or SIPLANT service port (typically 80/443 or other web service port)
  • No authentication required
remotely exploitableno authentication requiredlow complexityhigh CVSS (8.6)information disclosure
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
SIMOVE Fleetmanager V3.1 < V3.1.13< 3.1.133.1.13
SIMOVE Fleetmanager V3.2 < V3.2.4< 3.2.43.2.4
SIMOVE Fleetmanager V3.3 < V3.3.2< 3.3.23.3.2
SIMOVE Fleetmanager V4.0 < V4.0.1< 4.0.14.0.1
SIPLANT V1.7All versionsFix available
SIPLANT V2.2All versionsFix available
SIPLANT V3.0All versionsFix available
SIPLANT V3.1 < V3.1.4< 3.1.43.1.4
Remediation & Mitigation
0/4
Do now
0/2
WORKAROUNDRestrict network access to SIMOVE Fleetmanager and SIPLANT services to only authorized administrative networks and workstations using firewall rules
HARDENINGConfigure user management to restrict service access rights to only necessary project files, removing unnecessary read access to sensitive directories
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate SIMOVE Fleetmanager to the latest available version for your branch: V3.1.13 or later, V3.2.4 or later, V3.3.2 or later, or V4.0.1 or later
HOTFIXUpdate SIPLANT to V3.1.4 or later; contact Siemens support at siplant-support.de@siemens.com for upgrade options for end-of-life versions (1.7, 2.2, 3.0)
API: /api/v1/advisories/37dd034c-7315-4dec-a75b-41206b586894

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.