Johnson Controls XAAP Android

Summary

A cleartext storage vulnerability has been identified in Johnson Controls XAAP Android versions prior to 1.53. Successful exploitation could allow an attacker with physical access to the device to obtain confidential information stored locally in plaintext. Johnson Controls recommends updating to version 1.53 or later and implementing physical access restrictions and device hardening measures.

IFF Assessment

FOE

This vulnerability allows for the unauthorized access and exfiltration of sensitive data from affected devices, directly harming defenders by exposing confidential information.

Severity

3.3 Low

The CVSS score of 3.3 reflects a low severity, primarily due to the 'Cleartext Storage of Sensitive Information' vulnerability which requires physical access to the device and potentially an additional exploit to gain the necessary privileges to read the plaintext data.

Defender Context

This advisory highlights the risk of sensitive data being stored unencrypted on devices, making it vulnerable to local attackers. Defenders should ensure devices running this software are physically secured and that encryption and other hardening measures are enforced to mitigate the impact of such vulnerabilities.

Read Full Story →