Full Report
[Control Systems] Johnson Controls security advisory (AV26-991)
Analysis Summary
# Vulnerability: Multiple Flaws in Johnson Controls EasyIO Series
## CVE Details
- **CVE ID:** [Not explicitly detailed in source text]*
- **CVSS Score:** [Not specified]*
- **CWE:** [Not specified]*
*\*Note: The provided advisory summary (AV26-991) refers to a collection of vulnerabilities addressed in the October 2026 update cycle. Specific CVE identifiers were not listed in the provided snippet.*
## Affected Systems
- **Products:**
- EasyIO FG
- EasyIO Neo
- EasyIO FS32
- **Versions:**
- **EasyIO FG:** All versions prior to 2.0b52
- **EasyIO Neo:** All versions prior to 3.3b63 and 3.3b25
- **EasyIO FS32:** All versions prior to 3.0b63 and 3.3b63
- **Configurations:** Default installations of the affected EasyIO controller firmware.
## Vulnerability Description
While the specific technical mechanics (e.g., Buffer Overflow, SQLi) are not detailed in the brief, these vulnerabilities affect the firmware of EasyIO building automation controllers. Based on the advisory classification (AV26-991), these flaws typically involve unauthorized access or remote code execution capabilities within the control system environment.
## Exploitation
- **Status:** Not explicitly stated as exploited in the wild (Information based on standard advisory release).
- **Complexity:** [Not specified]
- **Attack Vector:** [Likely Network/Adjacent - standard for Control Systems]
## Impact
- **Confidentiality:** High (Potential access to building configuration data)
- **Integrity:** High (Potential to alter control logic)
- **Availability:** High (Potential to cause device denial-of-service)
## Remediation
### Patches
Johnson Controls recommends updating to the following firmware versions or newer:
- **EasyIO FG:** Update to version **2.0b52**
- **EasyIO Neo:** Update to version **3.3b63** or **3.3b25** (depending on hardware revision)
- **EasyIO FS32:** Update to version **3.0b63** or **3.3b63**
### Workarounds
- Ensure EasyIO controllers are not exposed directly to the public internet.
- Implement network segmentation (VLANs) to isolate Building Management Systems (BMS) from corporate networks.
- Use VPNs with multi-factor authentication for remote access to control systems.
## Detection
- Monitor for unusual administrative login attempts or unauthorized configuration changes in the EasyIO management interface.
- Audit network traffic for unexpected communication between the controllers and external IP addresses.
## References
- Johnson Controls - Product Security Advisories: hxxps[://]www[.]johnsoncontrols[.]com/trust-center/cybersecurity/security-advisories
- Cyber Centre Advisory (AV26-991): hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/control-systems-johnson-controls-security-advisory-av26-991