Executive brief
Siemens SIMOVE Fleetmanager and SIPLANT are industrial management and automation platforms used in critical manufacturing environments worldwide. An unauthenticated attacker on the network can exploit a path traversal flaw to read arbitrary files from the server, potentially obtaining database passwords, API keys, private encryption keys, and sensitive operational configuration. This could lead to further system compromise, credential theft, and exposure of critical infrastructure security controls.
Technical details
The vulnerability is a relative path traversal (CWE-23) in the file-serving endpoint of the embedded HTTP server. The affected devices do not properly validate and neutralize directory traversal sequences, permitting an unauthenticated remote attacker to bypass directory restrictions and access arbitrary files. The attack vector is network-based with no authentication or user interaction required; the attacker can directly craft HTTP requests with traversal payloads (e.g., "../../../etc/passwd") to exfiltrate sensitive files. Siemens has released patched versions: SIMOVE Fleetmanager V3.1.13, V3.2.4, V3.3.2, V4.0.1, and SIPLANT V3.1.4 address the vulnerability. Network segmentation and file-level access control are interim mitigations.
Affected products
- Siemens SIMOVE Fleetmanager V3.1 < 3.1.13, V3.2 < 3.2.4, V3.3 < 3.3.2, V4.0 < 4.0.1
- Siemens SIPLANT V1.7, V2.2, V3.0, V3.1 < 3.1.4
Timeline
- 2026-09-22: disclosed: CISA republication of Siemens ProductCERT SSA-517424
- 2026-09-08: other: Original Siemens ProductCERT advisory publication date
- 2026-09-08: patched: Siemens released patched versions