Executive Summary

CVE-2026-67367 is an unauthenticated directory traversal flaw in the file-serving endpoint of the embedded HTTP server used by SIMOVE Fleetmanager and SIPLANT, allowing a remote attacker to read arbitrary files from the host filesystem without credentials. In an OT context, that means configuration files, credential stores, and process data can be exfiltrated before any authentication boundary is engaged, which converts a management server into a reconnaissance pivot for deeper attacks on connected fleet and plant assets.

Technical Exposure Breakdown

The vulnerable component is the file-serving endpoint of the embedded HTTP server. Per the source data, affected devices do not properly validate and neutralize directory traversal sequences, meaning encoded or literal ../ sequences in a request path allow the server to resolve outside the intended web root. The attack vector is network based and pre-authentication. There is no requirement for a valid session, a stolen token, or an established trust relationship. An attacker who can route a TCP connection to the HTTP listener can request files by traversing up the directory tree.

The CVSS score of 8.6 reflects the combination of remote reach, no privileges required, and no user interaction, weighted against a confidentiality-only outcome. Directory traversal that only reads files does not directly write to disk or execute code, but the practical impact depends entirely on what those files contain. Fleet and plant management platforms routinely store database connection strings, service account credentials, API keys, certificate private keys, and device inventory data in predictable locations. Reading any of these turns a read-only flaw into the first stage of a credential-based intrusion.

The affected version ranges are enumerated in the advisory across SIMOVE Fleetmanager V3.1, V3.2, V3.3, and V4.0, and across SIPLANT V1.7, V2.2, V3.0, and V3.1. Several SIPLANT branches are listed as affected across all versions. Operators should treat the presence of these products on any routable segment as an active exposure until each instance is confirmed patched or isolated.

OT Impact and Compliance Risk

The physical risk here is indirect but real. These platforms coordinate fleet and plant assets, so file disclosure that yields operational credentials can lead to unauthorized control actions downstream. An attacker reading a configuration file that maps device endpoints and embedded credentials gains the exact information needed to issue commands to the equipment those platforms manage.

Under IEC 62443, an unauthenticated remote read path violates the zone and conduit assumptions that underpin segmentation. Under NERC CIP, if these servers reside inside an Electronic Security Perimeter or hold BES Cyber System Information, the disclosure exposure maps directly to CIP-011 information protection failures. For water and wastewater operators subject to AWIA 2018 requirements, and for pipeline operators under TSA SD-02C, the same logic applies: an unauthenticated file read on a management host undermines the access control and segmentation controls those frameworks mandate.

Compensating Controls

Do not treat active scanning as a safe discovery method here. Probing embedded HTTP servers on industrial components with unexpected request patterns can hang or crash the service and disrupt the process it manages. Identify affected assets from passive network monitoring and asset inventory records instead.

The immediate control is to remove the HTTP endpoint from any network reachable by untrusted hosts. Place these servers behind a segmentation boundary that only permits engineering workstations on an allowlist. Where the endpoint must remain reachable, front it with a reverse proxy or application gateway that normalizes and rejects path traversal sequences before they reach the embedded server.

A virtual patch at the network layer is the fastest mitigation. A Suricata rule concept: inspect HTTP request URIs on the relevant listener ports for encoded and literal traversal patterns such as ../, ..%2f, and %2e%2e sequences, and drop or alert on matches destined for the file-serving path. This blocks the exploit primitive independent of vendor fix timelines, which the grounding data lists as unknown for this advisory. Pair the rule with strict egress filtering so that even a successful read cannot exfiltrate to arbitrary external destinations.

BreachSpider Intel

BreachSpider tracks exploitation signals and advisory revisions for CVE-2026-67367 and related ICS exposures so OT teams can prioritize compensating controls before a working exploit reaches their perimeter.