Cleartext Storage Vulnerability in Johnson Controls Simplex Incident Manager and Autocall Fire Administrator
CVE-2026-27875

6.9MEDIUM

What is CVE-2026-27875?

An issue has been identified in Johnson Controls' Simplex Incident Manager and Autocall Fire Administrator, where sensitive data may be stored in cleartext form in memory. This flaw could potentially allow attackers to retrieve embedded sensitive data, posing risks to information integrity and confidentiality. Users are advised to apply updates to the affected products to mitigate potential exposure. For further information, visit the Johnson Controls security advisory page.

Affected Version(s)

Simplex Incident Manager / Autocall Fire Administrator 0 < 2.01.05

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.