{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-67367/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-67367"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SIMOVE Fleetmanager (\u003c 3.1.13, 3.2.4, 3.3.2, 4.0.1)","SIPLANT (\u003c 3.1.4)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-67367","path-traversal","industrial-security","siemens"],"_cs_type":"advisory","_cs_vendors":["Siemens"],"content_html":"\u003cp\u003eSiemens has disclosed a critical path traversal vulnerability, identified as CVE-2026-67367, affecting multiple versions of SIMOVE Fleetmanager and SIPLANT. The vulnerability exists within the file-serving endpoint of the products' embedded HTTP server, which fails to properly validate and neutralize directory traversal sequences. This weakness allows an unauthenticated, remote attacker to traverse the file system and access arbitrary files located outside of the intended directory scope on the host operating system. Successful exploitation could lead to the unauthorized disclosure of sensitive information, including configuration secrets, private cryptographic keys, and credential stores. This vulnerability is particularly critical given the products' deployment in the Critical Manufacturing sector. Siemens has released patches for the affected versions and recommends that users update their systems to the latest available releases immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to operational security within the Critical Manufacturing sector. Successful exploitation allows an unauthenticated remote attacker to gain unauthorized access to sensitive files on the host system. The exposure of credential stores, private keys, and configuration secrets could facilitate further lateral movement, persistent access, or compromise of connected industrial control systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade SIMOVE Fleetmanager and SIPLANT to the versions identified as patched by Siemens (e.g., V3.1.13, V3.2.4, V3.3.2, V4.0.1, or V3.1.4 respectively).\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation to ensure these devices are not accessible from the public internet.\u003c/li\u003e\n\u003cli\u003eUtilize VPNs for secure remote access if necessary, ensuring the VPN infrastructure itself is patched and monitored.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege by configuring user management to restrict service-level access rights to project files.\u003c/li\u003e\n\u003cli\u003eMonitor logs for HTTP requests containing directory traversal patterns (e.g., ../, .., /etc/passwd) targeting embedded web servers in OT environments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T16:47:09Z","date_published":"2026-09-22T16:47:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-siemens-path-traversal/","summary":"An unauthenticated path traversal vulnerability (CVE-2026-67367) in Siemens SIMOVE Fleetmanager and SIPLANT allows remote attackers to read arbitrary files from the underlying operating system.","title":"Path Traversal Vulnerability in Siemens SIMOVE and SIPLANT","url":"https://feed.craftedsignal.io/briefs/2026-09-siemens-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-67367","version":"https://jsonfeed.org/version/1.1"}