Cyber Resilience
← All news
Confirmed

Johnson Controls XAAP Android

Johnson Controls fixed a cleartext storage vulnerability in XAAP Android versions before 1.53. Update to 1.53 or later if you use it.
Sources (2)
What this means for you — CISO:If you run Johnson Controls XAAP Android below 1.53 or C-CURE 9000/victor at the listed versions, apply the vendor updates. Treat the server products as higher priority: network access can yield RCE; the mobile app issue is cleartext storage of sensitive data.
What this means for you — Lean IT orgs:These are Johnson Controls building-access and security products, not general business software. Most lean-IT shops do not run them—if your facility or landlord does, ask who owns patching and confirm XAAP is at 1.53+ and servers are past the affected versions.
What this means for you — MSP:Inventory clients for Johnson Controls XAAP Android, C-CURE 9000, and victor application server. Prioritize patching the server RCE path; where the mobile app is deployed, push XAAP to 1.53 or later.
What this means for you — Researcher:CISA ICSA-26-204-01 and ICSA-26-204-02 cover RCE on C-CURE 9000/victor and cleartext storage on XAAP Android (CVSS 3.3). Review the CSAF for exact version bounds and attack preconditions.