{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/simplex-incident-manager-2.01/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Simplex Incident Manager (2.01)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Johnson Controls"],"content_html":"\u003cp\u003eJohnson Controls has disclosed a vulnerability in the Simplex Incident Manager application, identified as CVE-2026-27875. The application insecurely stores user passwords and authentication tokens in cleartext within system memory during runtime. This vulnerability (CWE-316) impacts all versions of the product up to and including V2.01. An attacker who has achieved local access to the host system can leverage memory-dumping utilities or perform forensics on memory captures to retrieve these credentials. Given the role of Simplex Incident Manager in managing building automation and incident response, compromised credentials could lead to unauthorized access to the broader building automation infrastructure. Successful exploitation requires an attacker to already possess local access to the system with low-level privileges, and the exploitation has a high attack complexity rating.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-27875 enables a local attacker to extract high-value credentials, potentially bypassing authentication to gain administrative control over the Simplex Incident Manager application. The impact is significant for organizations across the critical infrastructure sectors, including manufacturing, energy, and transportation, as unauthorized access could result in manipulation of safety and security systems. No exploitation has been reported in the wild.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Simplex Incident Manager to version v2.01.01 or later to remediate CVE-2026-27875.\u003c/li\u003e\n\u003cli\u003eRestrict local interactive access to servers running Simplex Incident Manager to authorized personnel only to prevent the execution of memory-scraping tools.\u003c/li\u003e\n\u003cli\u003eImplement and enforce the principle of least privilege on host operating systems to prevent local users from performing unauthorized process memory dumps.\u003c/li\u003e\n\u003cli\u003eDeploy endpoint protection solutions configured to detect and block known memory-dumping utilities (e.g., Mimikatz, Procdump, or custom memory-scraping scripts).\u003c/li\u003e\n\u003cli\u003eEnable full-disk encryption and secure boot to mitigate risks associated with physical access and offline memory analysis.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T18:11:26Z","date_published":"2026-08-20T18:11:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-simplex-incident-manager/","summary":"Johnson Controls Simplex Incident Manager versions 2.01 and earlier store sensitive user credentials in memory, allowing a local attacker with low privileges to extract them via memory analysis.","title":"Cleartext Credential Storage in Johnson Controls Simplex Incident Manager","url":"https://feed.craftedsignal.io/briefs/2026-08-simplex-incident-manager/"}],"language":"en","title":"CraftedSignal Threat Feed - Simplex Incident Manager (2.01)","version":"https://jsonfeed.org/version/1.1"}