The Cybersecurity and Infrastructure Security Agency (CISA) and Siemens ProductCERT have issued security advisory ICSA-26-265-07 (SSA-517424) alerting industrial asset owners to a high-severity path traversal vulnerability (CVE-2026-67367, CVSS 8.6) in Siemens SIMOVE Fleetmanager and SIPLANT. The software platform, deployed across automotive plants and automated distribution centers to orchestrate autonomous automated guided vehicles (AGVs), allows unauthenticated network attackers to read arbitrary files from supervisory host servers.
Industrial Surface: AGV Fleet Control & Production Disruption
Siemens SIMOVE is an enterprise framework for controlling and optimizing fleets of automated guided vehicles, mobile robots, and autonomous tuggers within industrial manufacturing plants. The SIMOVE Fleetmanager software runs on industrial PCs and supervisory servers, calculating collision-free navigation paths, managing fleet dispatch queues, and synchronizing with plant-floor Programmable Logic Controllers (PLCs) over industrial Wi-Fi and 5G networks.
Because AGV systems handle material transport directly adjacent to human assembly lines, unauthorized tampering with navigation data, map coordinate files, or communication tokens introduces severe occupational safety risks and production stoppage vectors.
Vulnerability Mechanics & Path Traversal (CWE-22)
The defect is cataloged under CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'). SIMOVE Fleetmanager exposes a web-based management API on internal HTTP endpoints. When processing client requests for project resources, documentation, or map layers, the file-serving endpoint fails to properly sanitize dot-dot-slash (../) path sequences.
An attacker capable of dispatching HTTP requests to the SIMOVE listener can escape the web root and retrieve sensitive operational configuration files, Windows SAM database hashes, or fleet security tokens:
# HTTP Request demonstrating path traversal on vulnerable SIMOVE Fleetmanager endpoint
GET /api/v1/project/resources?file=..%2f..%2f..%2f..%2fProgramData%2fSiemens%2fSIMOVE%2fconfig%2ffleet_auth.json HTTP/1.1
Host: 192.168.10.50:8080
User-Agent: Mozilla/5.0
Accept: */*
The server responds with HTTP 200 and streams the requested JSON payload containing database authentication credentials, PLC cryptographic keys, and vehicle coordinate offsets.
Affected Installations & Risk Profile
| Advisory Specification | Vulnerability Metric |
|---|---|
| Advisory Identifier | ICSA-26-265-07 / Siemens SSA-517424 |
| CVE Identifier | CVE-2026-67367 |
| CVSS v3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| CVSS Base Score | 8.6 (High) |
| Affected Versions | SIMOVE Fleetmanager V3.1 < V3.1.13, V3.2 < V3.2.4, V3.3 < V3.3.2, V4.0 < V4.0.1; SIPLANT < V3.1.4 |
| Exploitation Preconditions | Network access to SIMOVE Fleetmanager HTTP web service |
Remediation Playbook for OT Network Engineers
Automation directors and manufacturing cybersecurity personnel must implement the following safeguards:
1. Deploy Siemens Security Updates
Upgrade SIMOVE Fleetmanager and SIPLANT to the latest maintenance releases:
- SIMOVE Fleetmanager V3.1: Update to V3.1.13 or later
- SIMOVE Fleetmanager V3.2: Update to V3.2.4 or later
- SIMOVE Fleetmanager V3.3: Update to V3.3.2 or later
- SIMOVE Fleetmanager V4.0: Update to V4.0.1 or later
2. Restrict Host Service Account File Permissions
Reconfigure the Windows service running SIMOVE Fleetmanager to execute under a dedicated low-privileged service account. Remove read permissions on system configuration folders outside the designated application sandbox.
3. Purdue Model Segmentation & Firewalling
Isolate AGV wireless networks within Purdue Model Level 2 (Cell Control) VLANs. Block all direct routing between SIMOVE fleet servers and corporate IT enterprise subnets.



