news.mlab.sh
Back to the feed
vulnerability

Siemens SIMOVE Fleetmanager and SIPLANT

HighCVSS 8.6
Summary

Siemens has released security advisories regarding a path traversal vulnerability in its SIMOVE Fleetmanager and SIPLANT products. This vulnerability allows an unauthenticated remote attacker to read arbitrary files from the underlying operating system, potentially exposing sensitive data like credential stores and private keys. Affected versions range from V3.1.13 to V4.0.1, and Siemens recommends updating to the latest versions to mitigate the risk. The vulnerability was reported by Siemens ProductCERT and is being addressed through vendor updates and general security best practices.

Siemens has identified and announced a critical path traversal vulnerability within its SIMOVE Fleetmanager and SIPLANT products. This vulnerability stems from a failure to properly validate directory traversal sequences in the file-serving endpoint of the embedded HTTP server. Consequently, an unauthenticated remote attacker can access files outside of the intended scope, potentially exposing sensitive data such as credential stores and private keys. The vulnerability affects a range of versions, including V3.1.13, V3.2.4, V3.3.2, V4.0.1, and others listed in the advisory. Siemens ProductCERT reported this issue, and the company is providing updates and recommendations to address the risk.

**What happened** The vulnerability allows an attacker to bypass security restrictions and access files located outside of the intended directory structure. This could lead to the exposure of confidential information stored on the device, including user credentials and potentially private keys.

**Technical details**

  • **Affected products:** Siemens SIMOVE Fleetmanager and SIPLANT
  • **Affected versions:** SIMOVE Fleetmanager V3.1 < V3.1.13, SIMOVE Fleetmanager V3.2 < V3.2.4, SIMOVE Fleetmanager V3.3 < V3.3.2, SIMOVE Fleetmanager V4.0 < V4.0.1, SIPLANT V1.7, SIPLANT V2.2, SIPLANT V3.0, SIPLANT V3.1 < V3.1.4
  • **Vulnerability type:** CWE-23 Relative Path Traversal
  • **CVSS Score:** Not specified
  • **Attack Vector:** Remote, Unauthenticated

**Impact** The vulnerability poses a significant risk to critical infrastructure sectors, particularly those relying on Siemens’ industrial control systems. Successful exploitation could lead to data breaches, unauthorized access to sensitive information, and potential disruption of industrial operations. The vulnerability could be used to gain control of devices and potentially compromise entire systems.

**What to do**

  • **Update:** Siemens strongly recommends updating to the latest versions of SIMOVE Fleetmanager and SIPLANT (V3.1.13 or later, V3.1.4 or later, V3.2.4 or later, V3.3.2 or later, V4.0.1 or later).
  • **Network Segmentation:** Restrict network access to affected devices.
  • **User Management:** Configure appropriate user management to limit service access to project files.
  • **General Security:** Implement Siemens’ operational guidelines for Industrial Security and follow recommendations in product manuals. Refer to the associated Siemens security advisory SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - CSAF Version, and SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - HTML Version.

**Why it matters** This vulnerability highlights the importance of robust security practices within industrial control systems. The potential for unauthorized access to sensitive data and system compromise underscores the need for proactive vulnerability management and ongoing security monitoring. Siemens’ response demonstrates a commitment to addressing security concerns and providing guidance to its customers.

Read the full article at CISA Advisories