Illustrative image generated with AI
Cleartext Credentials in Memory: Johnson Controls Fixes Medium-Severity Flaw in Simplex Incident Manager
Johnson Controls fixes medium-severity flaw CVE-2026-27875 in Simplex Incident Manager, preventing cleartext credential extraction from memory. Update recommended.
Text generated by artificial intelligence, published without human review. AI transparency
On August 20, 2026, CISA published advisory ICSA-26-232-01, which draws on the Johnson Controls Product Security Advisory JCI-PSA-2026-28. The report covers CVE-2026-27875, a CWE-316 vulnerability in the Simplex Incident Manager software. The flaw allows a local low-privileged user to extract authentication credentials from system memory.
Discovery and Publication
The vulnerability was reported directly to CISA by Johnson Controls Inc., a company headquartered in Ireland with global distribution. The vendor operates in critical sectors, including critical manufacturing, commercial facilities, government services and facilities, transportation systems, and energy. The advisory is the initial republication of JCI-PSA-2026-28.
At the time of publication, no known public exploits have been reported to CISA. The flaw is not remotely exploitable and requires high attack complexity. This reduces immediate risk but does not eliminate the need for remediation in environments managing critical infrastructure.
Products and Versions: An Inconsistent Picture
The CISA advisory identifies Johnson Controls Simplex Incident Manager as the affected product, with versions up to and including 2.01 (status “known_affected”). The NVD entry, however, identifies the product as “Simplex Incident Manager / Autocall Fire Administrator” and reports versions prior to 2.01.05 as affected.
The name Autocall Fire Administrator appears only in the NVD entry; the CISA advisory does not mention it. In addition, the version thresholds diverge: CISA refers to version <=2.01, while NVD refers to versions before 2.01.05. This difference should be taken into account when assessing exposure of your systems.
Technical Mechanism: CWE-316
The vulnerability is classified as CWE-316, “Cleartext Storage of Sensitive Information in Memory.” The application stores user credentials such as passwords and authentication tokens in cleartext in system memory during execution.
Anyone with local access to the system can attempt extraction. Memory dumping tools are sufficient, or in the case of insiders with elevated privileges, direct memory access. Successful exploitation allows a local attacker with low privileges to potentially gain unauthorized access to the application and connected systems.
Severity and Impact
Both CVSS scoring systems assign a base score of 5.8, MEDIUM severity.
CVSS v3.1: vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L. This means local attack, high complexity, low privileges required, no user interaction, and impact on the vulnerable component only. Confidentiality impact is high, integrity and availability impacts are low.
CVSS v4.0: vector CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N. The score is also 5.8. The v4 vector does not anticipate impacts on subsequent systems.
The concrete impact falls on systems running Simplex Incident Manager: a local user who extracts credentials can move laterally toward connected systems, increasing the risk of compromise of the incident management infrastructure.
It is not known whether the vulnerability has been added to CISA’s KEV catalog. At the time of publication, no public exploits are known. No information is available on recent Johnson Controls entries in KEV.
Updates and Mitigation Measures
Johnson Controls has released a corrected version. However, the indications about the resolving version are inconsistent across sources.
According to CISA, the corrected version is “v2.01.01,” but the same advisory recommends upgrading Simplex Incident Manager to version v1.01.05 or later. The NVD entry indicates affected versions “before 2.01.05,” implying that 2.01.05 is the fix threshold.
This divergence requires attention: before applying the update, you should verify the Product Security Advisory JCI-PSA-2026-28 on the vendor’s website.
In addition to the update, Johnson Controls and CISA recommend complementary defensive measures:
- Restrict local access to systems running Simplex Incident Manager to authorized personnel only.
- Implement endpoint protection and monitoring to detect memory dumping tools or suspicious processes.
- Apply strict access control policies and least privilege principles on hosts.
- Use full disk encryption and secure boot to reduce the risk of offline memory analysis.
- Monitor unauthorized local access attempts and enable audit logging.
Recommendations for ICS Operators
CISA recommends performing an impact analysis and risk assessment before applying defenses. For ICS environments, the agency highlights the importance of defense in depth and refers to document ICS-TIP-12-146-01B for industrial network protection strategies.
Operators should also report any suspicious activity to CISA for tracking and correlation. Anti-phishing and anti-social engineering countermeasures remain valid: do not open links or attachments in unsolicited emails.
The reference for detailed instructions is Johnson Controls’ security-advisories page: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories, with advisory JCI-PSA-2026-28.
Sources
This article is an original reworking based on the sources below.
