Cyber Resilience
← All news
Confirmed

Siemens SIMOVE Fleetmanager and SIPLANT

Our takeSiemens SIMOVE Fleetmanager V3.1 and SIPLANT have a path-traversal flaw that lets an attacker read files outside the intended directory. Siemens has published updated versions; apply them on your normal OT patch cycle.
Sources (1)
What this means for you — Security leader:Update all SIMOVE Fleetmanager V3.1 and SIPLANT instances to the latest Siemens release; the path-traversal flaw lets unauthenticated attackers read files outside the application root.
What this means for you — Lean IT orgs:If you run Siemens SIMOVE Fleetmanager or SIPLANT, update to the newest version immediately. Most small teams can do this through the vendor’s download portal or by asking your integrator.
What this means for you — MSP:Audit every client running Siemens SIMOVE Fleetmanager V3.1 or SIPLANT and push the vendor’s latest version; the path-traversal vulnerability is confirmed and gives file-system access outside the app.
What this means for you — Researcher:Siemens has published fixes for a path-traversal vulnerability (ICSA-26-265-07) in SIMOVE Fleetmanager V3.1 and SIPLANT; update all affected instances.