[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-siemens-patches-unauthenticated-file-read-bug-in-fleet-software":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},7221,"siemens-patches-unauthenticated-file-read-bug-in-fleet-software","Siemens Patches Unauthenticated File Read Bug in Fleet Software","An unauthenticated path traversal flaw in Siemens SIMOVE Fleetmanager and SIPLANT let attackers read arbitrary files, including credentials.","Siemens has patched a high-severity flaw that let anyone with network access to its fleet-management software read files off the underlying server without logging in.\n\nSiemens ProductCERT disclosed the vulnerability on September 8, 2026, and CISA republished the advisory two weeks later, on September 22. The bug, tracked as CVE-2026-67367, sits in the embedded HTTP server of SIMOVE Fleetmanager and SIPLANT, industrial software used to plan and manage vehicle and production fleets. It fails to strip directory-traversal sequences from file requests, so an unauthenticated remote attacker could walk outside the intended file scope and pull data like credential stores, private keys, and configuration secrets. CVSS scored it 8.6, and it affects SIMOVE Fleetmanager versions before 3.1.13, 3.2.4, 3.3.2, and 4.0.1, plus SIPLANT 1.7, 2.2, 3.0, and versions before 3.1.4. Siemens has shipped fixed builds for most of the lineup, though some SIPLANT versions require contacting customer support directly since there is no downloadable patch.\n\nThis is a plain old path-traversal bug, cataloged for decades as CWE-23, showing up in software that plans production and vehicle fleets for critical manufacturing operations worldwide. No authentication required, no user interaction needed - just network access to the device's web interface. That is the kind of low-effort, high-value target that gets scanned for the moment an advisory like this goes public.\n\nThe two-week gap between Siemens' original disclosure and CISA's republication is routine bureaucratic lag, not a cover-up, but it is still two extra weeks that unpatched systems sat exposed once the technical details were circulating.","[\"siemens\",\"ics-security\",\"path-traversal\",\"cve-2026-67367\"]","2026-09-22T12:00:00.000Z","2026-09-22T16:48:19.202Z","2026-09-22T16:48:25.110Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Fix the disclosure date: the source shows Siemens ProductCERT's SSA-517424 was originally published September 8, 2026, with CISA republishing it on September 22 — the draft incorrectly states 'disclosed on September 22,' so clarify that the vulnerability was disclosed September 8 and CISA republished it two weeks later.","resolved","security",[32,33,34,35],"siemens","ics-security","path-traversal","cve-2026-67367",[37],{"name":38,"url":39},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-265-07",0,{"sections":42},[43,48,52,57,62,67,72,76,81,86,91,96,101,106],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",4195,"2026-09-22T19:28:23.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":51},"Security",702,"2026-09-22T21:01:05.000Z",{"name":53,"slug":54,"count":55,"latest_published_at":56},"Policy","policy",366,"2026-09-22T18:04:41.000Z",{"name":58,"slug":59,"count":60,"latest_published_at":61},"Deals","deals",200,"2026-09-22T19:28:55.000Z",{"name":63,"slug":64,"count":65,"latest_published_at":66},"Hardware","hardware",167,"2026-09-22T20:00:00.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Science","science",131,"2026-09-22T16:26:30.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":66},"Consumer Tech","consumer-tech",110,{"name":77,"slug":78,"count":79,"latest_published_at":80},"Software","software",79,"2026-09-22T19:44:31.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Dev Tools","dev-tools",78,"2026-09-18T04:00:00.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Startups","startups",63,"2026-09-22T21:24:11.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Gaming","gaming",45,"2026-09-22T15:35:06.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"General","general",43,"2026-09-21T23:48:56.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"Reviews","reviews",27,"2026-09-22T13:00:00.000Z",{"name":107,"slug":108,"count":109,"latest_published_at":110},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]