Johnson Controls XAAP Android
A vulnerability exists in the Johnson Controls XAAP Android application, version 1.53 and earlier. Attackers with physical access to a device could potentially read sensitive data stored locally without encryption. This vulnerability is not exploitable remotely and requires physical access to the device. Johnson Controls recommends updating to version 1.53 or later and implementing additional security measures to mitigate the risk.
A critical vulnerability has been identified in the Johnson Controls XAAP Android application. Versions 1.53 and earlier are affected. The vulnerability stems from a cleartext storage weakness within the application, which stores sensitive data locally without encryption. This means that an attacker who gains physical access to a device running the vulnerable application could directly read this data in plaintext. Exploitation does not require network access, further increasing the risk. Johnson Controls has reported this vulnerability to CISA. The vulnerability is not exploitable remotely, but requires physical access to the device. Johnson Controls recommends users update the XAAP Android application to version 1.53 or later and implement additional security measures, including restricting physical access to devices, ensuring devices are hardened with up-to-date Android OS versions and device encryption, and utilizing Mobile Device Management (MDM) solutions to enforce security policies such as encryption requirements and application whitelisting. Organizations are encouraged to perform proper impact analysis and risk assessment prior to deploying defensive measures and to report any suspected malicious activity to CISA.