Impact
This vulnerability involves the cleartext storage of sensitive information in memory, enabling an attacker to retrieve embedded data. The flaw represents an improper handling of confidential data (CWE-316) and compromises confidentiality for any user or process that can access the affected application's memory space. No execution of code or denial of service is described; the primary consequence is unauthorized disclosure of data.
Affected Systems
Johnson Controls Simplex Incident Manager and Autocall Fire Administrator versions prior to 2.01.05 are affected. The vulnerability impacts installations of the Simplex Incident Manager and its companion Autocall Fire Administrator product.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation. However, because the flaw permits read access to sensitive data in memory, the confidentiality impact is significant. Successful exploitation would require the attacker to read either local memory or have sufficient privileges to access the relevant process memory, which may be possible in environments where the application runs with elevated rights or where memory can be read remotely. Therefore, the risk is moderate to high, and the vulnerability should be addressed promptly.
OpenCVE Enrichment