When the Incident Manager Becomes the Incident: CISA Flags Credential Leak in Johnson Controls Safety Software
The software organizations use to manage emergencies has itself become a security liability. CISA is warning that Johnson Controls' Simplex Incident Manager — versions 2.01 and earlier — stores passwords and authentication tokens unencrypted in system memory, where an attacker with even low-level local access can scrape them and pivot into connected systems. The tool designed to help you respond to a crisis could be the thing that starts one.
Bottom Line
This is a moderate-severity flaw with an outsized lesson: the systems built to manage crises are only as trustworthy as their own security hygiene, and this one was caught storing the keys to the kingdom in open memory. It's not a five-alarm emergency — local access is required — but it's a clean illustration of how a small foothold becomes a full compromise, and why physical-safety software deserves the same scrutiny as any other critical system. Organizations running affected versions should act on CISA's advisory now, not when it becomes convenient.