Skip to content

SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT - HTML Version

cert-portal.siemens.com September 22, 2026

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope.

Siemens has released new versions for the affected products and recommends to update to the latest versions.

Siemens has identified the following specific mitigations that customers can apply to reduce the risk:

Restrict network access to affected devices

Configure appropriate user management by restricting services' access rights to project files

Product-specific remediations or mitigations can be found in the section Known Affected Products . Please follow the General Security Recommendations .

As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: ), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at:

As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: ), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at:

SIMOVE Fleetmanager is a fleet management tool for automated guided vehicles (AGVs).

SIPLANT is a tool for Advanced Line Monitoring and can be used to collect, evaluate and analyze data from discrete production processes.

This chapter describes all vulnerabilities (CVE-IDs) addressed in this security advisory. Wherever applicable, it also documents the product-specific impact of the individual vulnerabilities.

Extracted Entities

CWE Weaknesses (1)

Domains (1)