Vendor
Cleartext Credential Storage in Johnson Controls Simplex Incident Manager
1 TTPJohnson Controls Simplex Incident Manager versions 2.01 and earlier store sensitive user credentials in memory, allowing a local attacker with low privileges to extract them via memory analysis.
Stored XSS Vulnerability in Johnson Controls Metasys
1 rule 1 TTPA stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-34491) in Johnson Controls Metasys allows low-privileged users to execute arbitrary scripts in the context of other users' sessions, potentially leading to session hijacking.
Johnson Controls Airwall Hard-coded Credentials and Path Traversal Vulnerabilities
3 TTPsJohnson Controls Airwall versions 4.0.4 and earlier are affected by CVE-2026-64887 and CVE-2026-34492, allowing attackers to potentially decrypt sensitive data or perform arbitrary file reads.
Critical Vulnerabilities in Johnson Controls C-CURE 9000 and victor
1 rule 1 TTP 3 CVEsMultiple vulnerabilities in Johnson Controls C-CURE 9000 and victor application servers, including .NET deserialization (CVE-2026-21655), allow unauthenticated remote code execution and unauthorized information disclosure.
Hardcoded Credentials in Johnson Controls TL280
Johnson Controls TL280 devices running firmware versions below 5.63 contain hardcoded credentials and utilize insecure cryptographic algorithms, potentially allowing unauthorized access.