[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjaFguD_cenAEazM7kSNcESEUb0hCoFnxFEOrhBZxwaY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"5962e1d5-cfdc-493f-ae3f-65ebc0ebc752","credential-extraction-flaw-in-johnson-controls-simplex-incident-manager-exposes-connected-systems","f06eaf32-e6e7-4fa3-89b0-751e93d968cb","Credential Extraction Flaw in Johnson Controls Simplex Incident Manager Exposes Connected Systems","A vulnerability in Johnson Controls Simplex Incident Manager (versions up to V2.01) allows low-privileged local attackers to extract user credentials directly from system memory, a technique commonly associated with tools like Mimikatz. This type of flaw is particularly dangerous in physical security and building management environments, where compromised credentials can cascade into unauthorized access across interconnected safety and operational systems. The availability of a patched version (v2.01.01) means organizations running unpatched instances are exposed to a known, documented attack path. Credential theft from memory is a critical stepping stone in lateral movement attacks, making timely patching and memory protection controls essential.","**Immediate Actions:**\n- Upgrade all Simplex Incident Manager instances to version v2.01.01 immediately to remediate the known vulnerability.\n- Restrict local system access to only authorized personnel using the principle of least privilege.\n- Deploy endpoint protection solutions capable of detecting credential-dumping behaviors (e.g., memory scraping).\n\n**Long-Term Improvements:**\n- Implement a formal vulnerability management program that tracks and prioritizes patching for OT\u002Fphysical security systems.\n- Enforce multi-factor authentication (MFA) on all applications that interface with critical building or safety systems.\n- Segment networks so that physical security management systems are isolated from broader corporate and IT infrastructure.\n\n**Detection Measures:**\n- Enable detailed logging and monitoring on endpoints running Simplex Incident Manager to detect anomalous memory access patterns.\n- Configure SIEM alerts for suspicious local account activity or privilege escalation events on systems hosting the application.\n- Conduct regular audits of user accounts and access rights tied to incident management platforms.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 7: Continuous Vulnerability Management","CIS Control 6: Access Control Management","CIS Control 3: Data Protection","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 SC-28: Protection of Information at Rest","NIST SP 800-53 IA-5: Authenticator Management","NIST Cybersecurity Framework DE.CM-8: Vulnerability Scans","IEC 62443-3-3: System Security Requirements for Industrial Automation","GDPR Article 32: Security of Processing (if EU personal data is involved)","published","2026-08-20T18:21:46.752724+00:00","2026-08-20T18:21:46.675+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-232-01","johnson-controls-simplex-incident-manager-70f227","Johnson Controls Simplex Incident Manager",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]