Johnson Controls EasyIO Neo Series EC and CW Controllers
Summary
Johnson Controls EasyIO Neo Series EC and CW Controllers are affected by CVE-2026-64892, a vulnerability that could allow attackers to gain access to sensitive information for further attacks. The affected product versions are specific to EC Controllers V3.3b63 and V3.3b62, and CW Controllers V3.3b25 and V3.3b24.
IFF Assessment
This vulnerability allows attackers to gain access to sensitive information, which can be used for further attacks, posing a risk to defenders.
Severity
The CVSS score of 3.5 indicates a low severity, primarily due to the 'Exposure of Sensitive Information' vulnerability. While it can be used to facilitate further attacks, it doesn't directly grant unauthorized access or control.
Defender Context
This vulnerability impacts building automation and control systems in critical infrastructure sectors. Defenders should monitor for any signs of information disclosure or reconnaissance attempts targeting these Johnson Controls devices and ensure affected versions are patched or mitigated as soon as possible.