IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Johnson Controls XAAP Android

LOW
CVSS 3.3
Date 2026-07-23T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-34490 3.3 low
A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. An attacker with physical access to the device and one able to compromise the device through a separate, unrelated flaw, could potentially read this data in plaintext. Exploitation does not require network access and is limited to the local device environment.

// Remediations (6)

Mitigation: Johnson Controls recommends users Avoid rooting or jailbreaking devices used in production environme
Johnson Controls recommends users Avoid rooting or jailbreaking devices used in production environments, as this weakens OS-level security controls that help protect local application data.
Mitigation: Johnson Controls recommends users ensure devices are hardened with up-to-date Android OS versions, d
Johnson Controls recommends users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place.
Mitigation: Johnson Controls recommends users restrict physical access to devices running the XAAP Android appli
Johnson Controls recommends users restrict physical access to devices running the XAAP Android application.
Patch: Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, whic
Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability.
Mitigation: Johnson Controls recommends users implement a Mobile Device Management (MDM) solution to enforce sec
Johnson Controls recommends users implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities.
Mitigation: For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-10.

// References