Johnson Controls EasyIO Neo Firmware V3.3b64 Fixes a Cleartext Login Flaw
Security / news
Johnson Controls EasyIO Neo Firmware V3.3b64 Fixes a Cleartext Login Flaw
Two CISA advisories on the same building controllers rate one flaw 3.5 and the other 5.4. The lower numbers depend on assumptions about where the controller sits.
A network attacker positioned between a browser and a Johnson Controls EasyIO Neo controller (and willing to wait for a user to log in) can read credentials and session data sent in cleartext. CISA published the advisory, CVE-2026-64893, on October 1, 2026 with a CVSS v3.1 score of 5.4. Johnson Controls has fixed it in firmware V3.3b64 for the EC series and V3.3b26 for the CW series.
The EasyIO Neo EC and CW controllers are programmable edge controllers for building automation. Two advisories, ICSA-26-274-04 and ICSA-26-274-05, cover the same firmware, and CISA credits Gabriele Gardois with both reports.
Affected firmware and the fixed versions
| Series | Affected versions | Fixed version |
|---|---|---|
| EasyIO Neo EC | V3.3b62, V3.3b63 | V3.3b64 |
| EasyIO Neo CW | V3.3b24, V3.3b25 | V3.3b26 |
Per CISA, the cleartext flaw "could allow an attacker to intercept and read sensitive information, including credentials and session data." The first advisory covers CVE-2026-64892, an exposure of sensitive information through a debug interface.
Two scores that understate the exposure
CVE-2026-64892 is rated 3.5 (low) on v3.1 and 4.8 (medium) on v4.0. Its vector requires high privileges and user interaction. FIRST's CVSS 3.1 specification defines high privileges as ones that give "significant (e.g., administrative) control over the vulnerable component," and user interaction as a case where a user must "take some action before the vulnerability can be exploited." A flaw that starts with an administrator is a thin one, and CISA's mitigation, physical access controls on debug ports, fits that reading.
CVE-2026-64893 is the more practical problem. Its v3.1 vector is network-reachable, high complexity, low privileges, user interaction required, with high confidentiality impact, scoring 5.4. The v4.0 score is 5.9, and its vector marks attack requirements as present and user interaction as passive, so the two scoring systems agree on medium while disagreeing on what the attacker has to do. On FIRST's scale, 4.0 to 6.9 is medium and 7.0 to 8.9 is high.
The score understates the risk where the web interface is served over HTTP on a flat building network. High attack complexity assumes the attacker needs a position on the path, and on an unsegmented network that position is cheap. That judgement is analysis, not a claim from CISA.
What to change on a deployed controller
CISA's mitigations for the cleartext flaw are concrete: enable and enforce HTTPS and TLS for all web-based management access, disable HTTP entirely, segment the network behind firewalls, use a VPN for remote access and apply the Johnson Controls hardening guidelines. Upgrading to V3.3b64 or V3.3b26 is listed first.
Both advisories report no known public exploitation as of October 1, 2026. CISA lists no workaround that avoids touching the firmware other than the network controls above.
The fix does not remove credentials already sent in cleartext. Operators who ran HTTP management on these controllers before upgrading have no way, from the advisories, to tell whether a session was captured, so rotating the controller passwords after the firmware update is a reasonable step. Neither advisory recommends it.
Other building and industrial advisories from the same day include the Zimbra SNMP bug and Citrix NetScaler CVE-2026-88771.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.