Johnson Controls EasyIO Neo Series EC and CW Controllers
Summary
Johnson Controls EasyIO Neo Series EC and CW Controllers are affected by CVE-2026-64893, a vulnerability allowing attackers to intercept and read sensitive information, including credentials and session data, transmitted in cleartext. This vulnerability impacts critical infrastructure sectors worldwide and could lead to technical or operational impact.
IFF Assessment
The vulnerability allows for the interception and reading of sensitive information, posing a direct threat to system security and data confidentiality.
Severity
The CVSS score of 5.4 is for 'Cleartext Transmission of Sensitive Information'. This score reflects a medium severity, indicating that while sensitive information can be intercepted, it may require some level of attacker interaction or access to the network.
Defender Context
Defenders should be aware of this vulnerability in Johnson Controls EasyIO Neo controllers, particularly if these devices are part of their critical infrastructure or building automation systems. Implementing network segmentation and monitoring for cleartext transmission of sensitive data are key mitigation strategies.