Johnson Controls EasyIO Neo Series EC and CW Controllers
CISA says Johnson Controls EasyIO Neo controllers transmit credentials in cleartext via CVE-2026-64893, with no known exploitation.
CISA republished Johnson Controls advisory JCI-PSA-2026-30 for EasyIO Neo Series EC and CW building-automation controllers. CVE-2026-64893 (CWE-319) could let a network attacker intercept credentials and session data sent in cleartext. Affected versions are EC V3.3b62 and V3.3b63 and CW V3.3b24 and V3.3b25. CVSS v3.1 is 5.4 (medium) with high attack complexity, and CISA reports no known public exploitation.
- CVE-2026-64893 is cleartext transmission of credentials and session data.
- Affects EasyIO Neo EC V3.3b62/b63 and CW V3.3b24/b25.
- CVSS v3.1 is 5.4 with high attack complexity.
- Controllers automate HVAC, lighting, and energy in commercial buildings.
- CISA reports no known public exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-648937.3—Cleartext Sensitive Data Transmission in EasyIO NEOpublished · Johnson Controls EasyIO NEO (Neo Series EC and CW controllers)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-64893 | Cleartext Sensitive Data Transmission in EasyIO NEO Johnson Controls EasyIO NEO building-automation controllers (Neo Series EC and CW) transmit sensitive information in cleartext in versions before 3.3b25. A network attacker who can position themselves in the path of that traffic can perform a man-in-the-middle attack and read the unprotected data. CVSS 4.0 rates the issue 7.3 (high): it is network-reachable but high complexity, needs preconditions, low privileges, and passive user interaction, with high confidentiality impact on the device and high subsequent-system impact. Operators of EasyIO NEO devices older than 3.3b25 are affected. It is not in CISA KEV, and no public proof-of-concept is known. Upgrade Johnson Controls EasyIO NEO (Neo Series EC and CW controllers) to version 3.3b25 or later. Until then, keep management and control traffic on a segmented, trusted network and do not expose these controllers directly to untrusted networks. After patching, confirm the device is no longer sending credentials or other sensitive data in cleartext. |
Full article479 words · extracted from cisa.gov · click to collapse
Summary
Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data.
The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected:
- EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64893)
- EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64893)
- EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64893)
- EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64893)
| CVSS | Vendor | Equipment | Vulnerabilities |
|---|---|---|---|
| v3 5.4 | Johnson Controls | Johnson Controls EasyIO Neo Series EC and CW Controllers | Cleartext Transmission of Sensitive Information |
Background
- Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Ireland
Vulnerabilities
CVE-2026-64893
Johnson Controls is aware of a vulnerability in EasyIO Neo which may allow an attacker to intercept and read sensitive information, including credentials and session data, transmitted in cleartext over the network. Successful exploitation could result in technical or operational impact. EasyIO Neo is a programmable building automation edge controller used to manage and automate HVAC, lighting, and energy systems in commercial buildings through a web-based interface.
Affected Products
Johnson Controls EasyIO Neo Series EC and CW Controllers
Vendor:
Johnson Controls
Product Version:
Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25
Product Status:
known_affected
Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information
Metrics
| CVSS Version | Base Score | Base Severity | Vector String |
|---|---|---|---|
| 3.1 | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N |
| 4.0 | 5.9 | MEDIUM | CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N |
Acknowledgments
- Gabriele Gardois reported this vulnerability to Johnson Controls
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.
Revision History
- Initial Release Date: 2026-10-01
| Date | Revision | Summary |
|---|---|---|
| 2026-10-01 | 1 | Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-30 |