Johnson Controls Simplex Incident Manager

Summary

Johnson Controls Simplex Incident Manager versions prior to V2.01 are affected by a vulnerability (CVE-2026-27875) that allows local attackers to extract user credentials from system memory. Successful exploitation could lead to unauthorized access to the application and connected systems.

IFF Assessment

FOE

This vulnerability allows attackers to extract sensitive user credentials, which can lead to unauthorized access and further compromise of connected systems.

Severity

5.8 Medium

The CVSS score of 5.8 reflects a Medium severity rating, indicating that while exploitation requires local access and low privileges, it can result in the disclosure of sensitive information, potentially leading to further unauthorized access.

Defender Context

This vulnerability in Johnson Controls Simplex Incident Manager poses a significant risk to critical infrastructure sectors by allowing attackers to steal credentials. Defenders should prioritize patching affected systems to the latest version and enforcing strict access controls to limit local system exposure.

Read Full Story →