Johnson Controls Simplex Incident Manager

MonitorCVSS 5.8ICS-CERT ICSA-26-232-01Aug 20, 2026
Johnson Controls
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

Johnson Controls Simplex Incident Manager versions 2.01 and earlier contain a vulnerability that allows a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory. Successful exploitation could grant unauthorized access to the application and connected building automation systems. Johnson Controls has released patched version v2.01.01 to address this issue.

What this means
What could happen
A local attacker with low privileges could extract user credentials from system memory, potentially gaining unauthorized access to the Incident Manager and connected building systems. This could allow them to alter alarm configurations, disable alerts, or access other networked systems that depend on this application.
Who's at risk
Building automation operators, facility managers, and IT staff responsible for Johnson Controls Simplex Incident Manager deployments in commercial buildings, campuses, hospitals, and industrial facilities. Anyone with administrative rights over these systems or who relies on alarm and event management functionality should prioritize credential protection.
How it could be exploited
An attacker with local access to the server running Simplex Incident Manager could use memory-dumping tools to extract cached credentials and authentication tokens from the running process. With these credentials, they could log in to the application or connected systems without needing the original password.
Prerequisites
  • Local access to the server running Simplex Incident Manager
  • Low-privilege user account on the host system
  • Ability to execute memory analysis tools on the host
Requires local access (reduces attack surface but not remote networks)Low privilege access required (common across user base)Memory credentials stored in plaintextNo authentication required for memory accessAffects alarm and event management system (could impact operational visibility)
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (1)
ProductAffected VersionsFix Status
Johnson Controls Simplex Incident Manager≤ V2.01No fix yet
Remediation & Mitigation
0/6
Do now
0/2
HARDENINGRestrict local access to servers running Simplex Incident Manager to authorized personnel only
HARDENINGEnable endpoint protection with memory-dumping tool detection and process monitoring
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

HOTFIXUpgrade Simplex Incident Manager to version v2.01.01 or later
HARDENINGEnforce least-privilege access policies on the host system; run the application with minimal required permissions
HARDENINGEnable audit logging and monitor for unauthorized local access attempts
Long-term hardening
0/1
HARDENINGEnable full-disk encryption and secure boot on servers running Simplex Incident Manager
API: /api/v1/advisories/0c68c5f2-1af5-439c-9df2-3e1b71c2a8d9

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.