<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-67367 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-67367/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 16:47:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-67367/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in Siemens SIMOVE and SIPLANT</title><link>https://feed.craftedsignal.io/briefs/2026-09-siemens-path-traversal/</link><pubDate>Tue, 22 Sep 2026 16:47:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-siemens-path-traversal/</guid><description>An unauthenticated path traversal vulnerability (CVE-2026-67367) in Siemens SIMOVE Fleetmanager and SIPLANT allows remote attackers to read arbitrary files from the underlying operating system.</description><content:encoded><![CDATA[<p>Siemens has disclosed a critical path traversal vulnerability, identified as CVE-2026-67367, affecting multiple versions of SIMOVE Fleetmanager and SIPLANT. The vulnerability exists within the file-serving endpoint of the products' embedded HTTP server, which fails to properly validate and neutralize directory traversal sequences. This weakness allows an unauthenticated, remote attacker to traverse the file system and access arbitrary files located outside of the intended directory scope on the host operating system. Successful exploitation could lead to the unauthorized disclosure of sensitive information, including configuration secrets, private cryptographic keys, and credential stores. This vulnerability is particularly critical given the products' deployment in the Critical Manufacturing sector. Siemens has released patches for the affected versions and recommends that users update their systems to the latest available releases immediately.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a high risk to operational security within the Critical Manufacturing sector. Successful exploitation allows an unauthenticated remote attacker to gain unauthorized access to sensitive files on the host system. The exposure of credential stores, private keys, and configuration secrets could facilitate further lateral movement, persistent access, or compromise of connected industrial control systems.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade SIMOVE Fleetmanager and SIPLANT to the versions identified as patched by Siemens (e.g., V3.1.13, V3.2.4, V3.3.2, V4.0.1, or V3.1.4 respectively).</li>
<li>Implement strict network segmentation to ensure these devices are not accessible from the public internet.</li>
<li>Utilize VPNs for secure remote access if necessary, ensuring the VPN infrastructure itself is patched and monitored.</li>
<li>Apply the principle of least privilege by configuring user management to restrict service-level access rights to project files.</li>
<li>Monitor logs for HTTP requests containing directory traversal patterns (e.g., ../, .., /etc/passwd) targeting embedded web servers in OT environments.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve-2026-67367</category><category>path-traversal</category><category>industrial-security</category><category>siemens</category></item></channel></rss>