Quick Links

    Decian blog

    Threat Advisories

    Understanding Cleartext Storage in Critical Manufacturing: The Johnson Controls XAAP Android Advisory

    Jake McDowell ยท 2026-07-27

    Mid-market organizations in the critical manufacturing sector operate with unique constraints. They balance operational uptime with the need for robust security, often relying on legacy systems or specialized industrial applications that do not always follow modern software development practices.

    A recent CISA advisory highlights a specific weakness in the Johnson Controls XAAP Android application, which is used in fire solutions and deployed globally. The core issue is a cleartext storage vulnerability. This means sensitive application data is saved locally on the device without encryption.

    The advisory notes that exploitation requires an attacker to have physical access to the device and to compromise the device through a separate, unrelated flaw. There is no remote exploitation vector. The CVSS score reflects this limited attack surface, classifying the risk as low to medium depending on the scoring methodology used. Despite the lower numerical score, the implications for a manufacturing environment are significant.

    For IT leaders and MSP partners, the concern is less about a hacker remotely stealing data and more about the physical security perimeter. In a facility where devices may be connected to critical infrastructure or accessible to maintenance personnel, a compromised device with unencrypted local data creates an attack vector for insider threats or opportunistic actors.

    If an attacker gains access to the device, they can read the data in plaintext. This could include configuration details, credentials, or other sensitive information that should never leave the device in an unprotected state. The vulnerability exists in versions of the application prior to 1.53.

    The remediation path is straightforward but requires disciplined execution. Johnson Controls has released a fix in version 1.53 and later. Simply updating the application removes the root cause of the cleartext storage issue. However, relying solely on a software patch is insufficient for a comprehensive defense strategy.

    Organizations must layer their security approach with hardening measures. This includes ensuring the underlying Android OS is up to date and that device-level encryption is active. Screen lock protections should also be enforced to prevent unauthorized access if the device is left unattended.

    For MSPs managing these assets across multiple client sites, Mobile Device Management (MDM) solutions are essential. An MDM allows for the enforcement of security policies, including encryption requirements, application whitelisting, and the capability to remotely wipe data if a device is lost or stolen.

    Another critical step is the prevention of rooting or jailbreaking. Devices used in production environments should never be modified in this way, as it weakens the operating system security controls that help protect local application data.

    CISA also recommends minimizing network exposure for all control system devices. These assets should not be accessible from the internet. Placing them behind firewalls and isolating them from general business networks adds a vital layer of defense. When remote access is necessary, secure methods like updated VPNs should be used, keeping in mind that the security of the connection is only as strong as the connected devices.

    There is no known public exploitation of this specific vulnerability at this time. This provides a window of opportunity for organizations to assess their inventory and implement the recommended defenses before a threat actor attempts to leverage the issue.

    The following checklist outlines the immediate actions IT leaders and security practitioners should take:

    Security is a continuous process, not a one-time fix. Addressing vulnerabilities like the one in Johnson Controls XAAP Android requires a combination of timely patching and strong operational security practices.

    Organizations seeking to strengthen their posture against these and other emerging threats can leverage specialized security services. Decian provides SOC and MDR capabilities designed to support mid-market IT teams and MSP partners in monitoring, detecting, and responding to cyber risks. Learn more about how we can assist your security operations at www.decian.com.

    ยฉ 2025 Decian, Inc. All rights reserved.