Impact
The vulnerability is a cleartext storage of sensitive data in the XAAP Application's local database on Android. The data is stored without encryption, allowing an attacker who gains local access to the device—such as through a jailbreak or other compromise—to retrieve confidential information. This can lead to privacy violations and potential misuse of the data. The weakness is classified as CWE‑312, Plaintext Storage of Sensitive Information.
Affected Systems
Customers running Johnson Controls XAAP Application on Android with a version earlier than 1.53 are affected. The vulnerability arises in the application's handling of local data storage. The affected product is the XAAP Application published by Johnson Controls for Android devices.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact, and the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not present in the CISA KEV catalog. Exploitation requires local device compromise; an adversary would need a jailbroken or otherwise compromised Android device to read the unencrypted database. While the risk to remote attackers is limited, operators should treat it as a moderate information‑disclosure risk that could be leveraged to obtain protected data.
OpenCVE Enrichment