AI analysis
Johnson Controls EasyIO NEO building-automation controllers (Neo Series EC and CW) transmit sensitive information in cleartext in versions before 3.3b25. A network attacker who can position themselves in the path of that traffic can perform a man-in-the-middle attack and read the unprotected data. CVSS 4.0 rates the issue 7.3 (high): it is network-reachable but high complexity, needs preconditions, low privileges, and passive user interaction, with high confidentiality impact on the device and high subsequent-system impact. Operators of EasyIO NEO devices older than 3.3b25 are affected. It is not in CISA KEV, and no public proof-of-concept is known.
What to do: Upgrade Johnson Controls EasyIO NEO (Neo Series EC and CW controllers) to version 3.3b25 or later. Until then, keep management and control traffic on a segmented, trusted network and do not expose these controllers directly to untrusted networks. After patching, confirm the device is no longer sending credentials or other sensitive data in cleartext.
Affected
| Johnson Controls EasyIO NEO (Neo Series EC and CW controllers) | before 3.3b25 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.