A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-67367 is a directory traversal vulnerability (CWE-23) affecting multiple versions of SIMOVE Fleetmanager and SIPLANT fleet management systems. The vulnerability exists in the file-serving endpoint of the embedded HTTP server, where insufficient validation of user-supplied input allows attackers to bypass intended directory restrictions. This impacts organizations using SIMOVE Fleetmanager V3.1 through V4.0 and SIPLANT V1.7 through V3.1 for fleet operations and management. With a CVSS score of 8.6, the vulnerability carries significant risk—attackers can read arbitrary files from affected systems, potentially exposing sensitive operational data, credentials, and system configurations critical to fleet management infrastructure.
While this CVE doesn't map to specific MITRE ATT&CK techniques, Casky's Claude-powered platform would identify the exploitation pattern through reconnaissance and credential access behaviors. Practitioners using Casky would observe attack signatures consistent with file system enumeration attempts, unusual directory traversal sequences (../ patterns) in HTTP request logs, and access attempts to system files outside normal application directories. The security skills mapped across Casky's 754 MITRE ATT&CK techniques would flag suspicious file access patterns and help practitioners distinguish legitimate fleet management operations from reconnaissance activity targeting sensitive configuration files or authentication data stored on vulnerable endpoints.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-67367. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation