Security & Threat Intelligence · 23.07.2026, 18:07 UTC
Johnson Controls XAAP Android
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA ICS Advisories · CISA Advisories ↗ |
| Veröffentlicht | 23.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-34490. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected:
XAAP Android <1.53
CVSS Vendor Equipment Vulnerabilities
v3 3.3 Johnson Controls Johnson Controls XAAP Android Cleartext Storage of Sensitive Information
Background
Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-34490
A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. An attacker with physical access to the device and one able to compromise the device through a separate, unrelated flaw, could potentially read this data in plaintext. Exploitation does not require network access and is limited to the local device environment. View CVE Details
Affected Products Johnson Controls XAAP Android
Vendor:Johnson Controls Product Version:Johnson Controls XAAP Android: <1.53 Product Status:known_affected
Remediations Vendor fixJohnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability. MitigationJohnson Controls recommends users restrict physical access to devices running the XAAP Android application. MitigationJohnson Controls recommends users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections …