Impact
An unauthenticated directory traversal flaw exists in the file‑serving endpoint of the embedded HTTP server in several Siemens SIMOVE Fleetmanager and SIPLANT devices. The flaw allows an attacker to inject traversal sequences that bypass normal path checks, enabling the read of arbitrary files on the underlying operating system. Confidentally, the attacker can retrieve credential stores, private keys, and configuration secrets, leading to a complete compromise of confidentiality.
Affected Systems
Affected are Siemens SIMOVE Fleetmanager versions 3.1 (before 3.1.13), 3.2 (before 3.2.4), 3.3 (before 3.3.2), 4.0 (before 4.0.1) and Siemens SIPLANT versions 1.7, 2.2, 3.0 in all releases and 3.1 up to (but not including) 3.1.4.
Risk and Exploitability
The CVSS score of 9.2 signals a very high impact threat. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based, via the public HTTP interface that does not require authentication. An attacker can send a crafted request such as GET /file?path=../../../../etc/passwd to the device and obtain file contents. Successful exploitation yields full read access to any file the device’s operating system permits.
OpenCVE Enrichment