View CSAF
Summary
Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.
The following versions of Johnson Controls Simplex Incident Manager are affected:
Simplex Incident Manager <=V2.01 (CVE-2026-27875)
CVSS
Vendor
Equipment
Vulnerabilities
v3 5.8
Johnson Controls Inc.
John…
📰 来源: CISA 安全公告
⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。