AI analysis
Johnson Controls Easy IO Neo building controllers before version 3.3b63 expose sensitive information that can be collected from common resource locations. The issue is reachable over the network with low complexity and no extra attack requirements, but it needs high privileges and only passive user interaction. On the controller itself the impact is limited (low confidentiality and availability, no integrity loss), yet data obtained this way can lead to high confidentiality, integrity, and availability impact on subsequent systems. Easy IO Neo Series EC and CW controllers running firmware older than 3.3b63 are affected. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Upgrade every Easy IO Neo controller (EC and CW series) to version 3.3b63 or later. Until then, limit management access to trusted networks and review privileged accounts, because exposed data can have high impact on systems reached after the controller.
Affected
| Johnson Controls Easy IO Neo (EC and CW series) | before 3.3b63 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.