Johnson Controls XAAP Android
p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-02.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. /strong /p p The following versions of Johnson Controls XAAP Android are affected: /p ul li XAAP Android lt;1.53 /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 3.3 /td td Johnson Controls /td td Johnson Controls XAAP Android /td td Cleartext Storage of Sensitive Information /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Ireland /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-34490 /a /h3 div class= csaf-accordion-content p A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. An attacker with physical access to the device and one able to compromise the device through a separate, unrelated flaw, could potentially read this data in plaintext. Exploitation does not require network access and is limited to the local device environment. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-34490 View CVE Details /a /p hr h4 Affected Products /h4 h5 Johnson Controls XAAP Android /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Johnson Controls /div div class= ics-version strong Product Version: /strong br Johnson Controls XAAP Android: lt;1.53 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability. /p p strong Mitigation /strong br Johnson Controls recommends users restrict physical access to devices running the XAAP Android application. /p p strong Mitigation /strong br Johnson Controls recommends users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place. /p p strong Mitigation /strong br Johnson Controls recommends users implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities. /p p strong Mitig
Sign in to read the full article
Create a free account to access all news, downloads, and community features
Originally published by CISA
Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02
This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.