Cyber Resilience
← All news
Confirmed

Siemens SIMOVE Fleetmanager and SIPLANT

Our takeSiemens SIMOVE Fleetmanager and SIPLANT have a path-traversal flaw that lets an attacker reach files outside the intended directory. Siemens shipped updated versions; update to the latest.
Sources (1)
What this means for you — Security leader:Siemens has released updates for SIMOVE Fleetmanager V3.1 and SIPLANT that fix a path traversal vulnerability allowing access to files outside the intended directory. Update affected systems immediately per the CISA advisory.
What this means for you — Lean IT orgs:If you run Siemens SIMOVE Fleetmanager or SIPLANT, apply the vendor's latest updates right away to close a path traversal flaw that lets attackers reach files they shouldn't.
What this means for you — MSP:Check client environments for Siemens SIMOVE Fleetmanager V3.1 or SIPLANT and schedule the vendor's patched versions; the path traversal issue is now public via CISA advisory.
What this means for you — Researcher:Siemens SIMOVE Fleetmanager V3.1 and SIPLANT contain a path traversal vulnerability; patched versions are available per the CISA ICS advisory.