Description
Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data.

This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.
Published: 2026-08-21
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Disclosure
Action: Immediate Patch
AI Analysis

Impact

This vulnerability involves the cleartext storage of sensitive information in memory, enabling an attacker to retrieve embedded data. The flaw represents an improper handling of confidential data (CWE-316) and compromises confidentiality for any user or process that can access the affected application's memory space. No execution of code or denial of service is described; the primary consequence is unauthorized disclosure of data.

Affected Systems

Johnson Controls Simplex Incident Manager and Autocall Fire Administrator versions prior to 2.01.05 are affected. The vulnerability impacts installations of the Simplex Incident Manager and its companion Autocall Fire Administrator product.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate risk. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation. However, because the flaw permits read access to sensitive data in memory, the confidentiality impact is significant. Successful exploitation would require the attacker to read either local memory or have sufficient privileges to access the relevant process memory, which may be possible in environments where the application runs with elevated rights or where memory can be read remotely. Therefore, the risk is moderate to high, and the vulnerability should be addressed promptly.

Generated by OpenCVE AI on August 21, 2026 at 19:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Simplx Incident Manager and Autocall Fire Administrator to version 2.01.05 or later.
  • Apply any vendor‑supplied patch that addresses cleartext memory storage.
  • Use automated scanning or log monitoring to ensure that no sensitive data remains exposed in memory after remediation.

Generated by OpenCVE AI on August 21, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Johnsoncontrols
Johnsoncontrols simplex Incident Manager / Autocall Fire Administrator
Vendors & Products Johnsoncontrols
Johnsoncontrols simplex Incident Manager / Autocall Fire Administrator

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.
Title Simplex Incident Manager Clear Test
First Time appeared Johnson Controls
Johnson Controls simplex Incident Manager Autocall Fire Administrator
Weaknesses CWE-316
CPEs cpe:2.3:a:johnson_controls:simplex_incident_manager_autocall_fire_administrator:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls simplex Incident Manager Autocall Fire Administrator
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:N/SA:N'}


Subscriptions

Johnson Controls Simplex Incident Manager Autocall Fire Administrator
Johnsoncontrols Simplex Incident Manager / Autocall Fire Administrator
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-08-21T20:08:37.055Z

Reserved: 2026-02-24T11:29:18.530Z

Link: CVE-2026-27875

cve-icon Vulnrichment

Updated: 2026-08-21T20:06:10.768Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-21T18:16:47.943

Modified: 2026-09-03T17:31:04.697

Link: CVE-2026-27875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:15:08Z

Weaknesses
  • CWE-316

    Cleartext Storage of Sensitive Information in Memory