CVE-2026-27875
Received
Received - Intake
Cleartext Storage of Sensitive Information in Simplex Incident Manager
Vulnerability report for CVE-2026-27875, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-21
Last updated on: 2026-08-21
Assigner: Johnson Controls
Description
Description
Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data.
This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| johnson_controls | simplex_incident_manager | to 2.01.05 (exc) |
| johnson_controls | autocall_fire_administrator | to 2.01.05 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-316 | The product stores sensitive information in cleartext in memory. |