Johnson Controls EasyIO Neo Series EC and CW Controllers

Summary

Johnson Controls EasyIO Neo Series EC and CW Controllers are affected by CVE-2026-64893, a vulnerability allowing attackers to intercept and read sensitive information, including credentials and session data, transmitted in cleartext. This vulnerability impacts critical infrastructure sectors worldwide and could lead to technical or operational impact.

IFF Assessment

FOE

The vulnerability allows for the interception and reading of sensitive information, posing a direct threat to system security and data confidentiality.

Severity

5.4 Medium

The CVSS score of 5.4 is for 'Cleartext Transmission of Sensitive Information'. This score reflects a medium severity, indicating that while sensitive information can be intercepted, it may require some level of attacker interaction or access to the network.

Defender Context

Defenders should be aware of this vulnerability in Johnson Controls EasyIO Neo controllers, particularly if these devices are part of their critical infrastructure or building automation systems. Implementing network segmentation and monitoring for cleartext transmission of sensitive data are key mitigation strategies.

Read Full Story →