Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT
Plan PatchCVSS 8.6SSA-517424Sep 8, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability (CWE-23) that allows an attacker with network access to read files outside of the intended application scope. An attacker could access sensitive project files, configuration data, or other files on the affected device without authentication.
What this means
What could happen
An attacker could access sensitive project files, configurations, and control system data on SIMOVE Fleetmanager or SIPLANT systems without credentials, potentially exposing process parameters, credentials, or other sensitive operational information.
Who's at risk
This affects organizations using SIMOVE Fleetmanager (versions 3.1, 3.2, 3.3, or 4.0) or SIPLANT (versions 1.7, 2.2, 3.0, or 3.1) for fleet management or plant operations data management. Information disclosure risk is highest if these systems are accessible from your corporate network or connected to process networks.
How it could be exploited
An attacker with network access to the SIMOVE Fleetmanager or SIPLANT web interface crafts a specially-formed request using path traversal techniques (e.g., "../" sequences) to access files outside the intended application directory. The vulnerability requires no authentication, allowing the attacker to read arbitrary files on the server.
Prerequisites
- Network access to SIMOVE Fleetmanager or SIPLANT service port (typically 80/443 or other web service port)
- No authentication required
remotely exploitableno authentication requiredlow complexityhigh CVSS (8.6)information disclosure
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
SIPLANT V1.7All versionsFix available
SIPLANT V2.2All versionsFix available
SIPLANT V3.0All versionsFix available
SIPLANT V3.1 < V3.1.4< 3.1.43.1.4
Remediation & Mitigation
0/4
Do now
0/2WORKAROUNDRestrict network access to SIMOVE Fleetmanager and SIPLANT services to only authorized administrative networks and workstations using firewall rules
HARDENINGConfigure user management to restrict service access rights to only necessary project files, removing unnecessary read access to sensitive directories
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXUpdate SIMOVE Fleetmanager to the latest available version for your branch: V3.1.13 or later, V3.2.4 or later, V3.3.2 or later, or V4.0.1 or later
HOTFIXUpdate SIPLANT to V3.1.4 or later; contact Siemens support at siplant-support.de@siemens.com for upgrade options for end-of-life versions (1.7, 2.2, 3.0)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/37dd034c-7315-4dec-a75b-41206b586894Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.