IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Johnson Controls Simplex Incident Manager

MEDIUM
CVSS 5.8
Date 2026-08-20T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-27875 5.8 medium
The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges.

// Remediations (3)

Mitigation: Aligning with CISA recommendations, Johnson Controls recommends taking steps to minimize risks to al
Aligning with CISA recommendations, Johnson Controls recommends taking steps to minimize risks to all building automation systems.
Mitigation: For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-28.
Mitigation: Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help re
Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.

// References