CVE-2026-67367

HIGH

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE ...

Affects 0 products across 1 vendor.

CVSS 3.18.6
CVSS v49.2
EPSS1.1%
Percentile64th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-23: CWE-23
Related Attack Patterns (CAPEC)
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-23
CAPEC-139 Relative Path Traversal
via CWE-23

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A high severity vulnerability (CVE-2026-67367) affects the target system. A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-67367?
A high severity vulnerability (CVE-2026-67367) affects the target system. A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1...
What is the CVSS score for CVE-2026-67367?
CVE-2026-67367 has CVSS 8.6 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N. EPSS: 1.1%.
Is CVE-2026-67367 actively exploited?
No confirmed active exploitation of CVE-2026-67367 as of 2026-09-25.
How do I remediate CVE-2026-67367?
Apply vendor patches for CVE-2026-67367. Monitor Siemens advisories.
What systems are affected by CVE-2026-67367?
CVE-2026-67367 affects: Siemens.
Vulnerability Details
CVE IDCVE-2026-67367
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Published2026-09-08
Last Modified2026-09-22
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Siemens &mdash; —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 20 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Siemens
CVE-2007-1917 10.0 Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library... CVE-2026-56451 10.0 A vulnerability has been identified in Opcenter X (All versions < V2604). Aff... CVE-2008-6916 10.0 Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to... CVE-2008-6993 10.0 Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allo... CVE-2011-4514 10.0 The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC...
View all Siemens CVEs →

Monitoring Siemens Vulnerabilities in Your Environment?

BreachSpider tracks every Siemens CVE and maps them to your ICS assets automatically. Get email or webhook alerts when a newly published Siemens vulnerability matches your assets.

Create a free account →