IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Johnson Controls EasyIO Neo Series EC and CW Controllers

LOW
CVSS 3.5
Date 2026-10-01T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-64892 3.5 low
Johnson Controls is aware of a vulnerability in EasyIO Neo Series EC and CW Controllers relating to an attacker gaining access to sensitive information that could be used to conduct further attacks against the system. The EC and CW are programmable edge controllers designed for building automation and control systems, used to manage and automate various building functions including HVAC, lighting, and energy management, supporting open protocols such as BACnet and Modbus for adaptable system connections.

// Remediations (4)

Mitigation: If immediate update is not possible, Johnson Controls recommends the following mitigations: Implemen
If immediate update is not possible, Johnson Controls recommends the following mitigations: Implement physical access controls to prevent unauthorized personnel from reaching device debug ports. Monitor network traffic to and from affected devices for unusual or unauthorized access attempts. Apply the principle of least privilege to all accounts and services that interact with the affected devices. Where possible, apply firmware updates that disable debug interfaces or require authentication before granting debug access. Implement intrusion detection/prevention systems to monitor for exploitation attempts. Refer to and follow all steps in the product hardening guide or the JCI universal hardening guide found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/resources. These mitigations reduce risk but may not fully remediate the vulnerability. Users should update to the fixed versions when operationally feasible.
Mitigation: Before applying updates in production ICS/OT environments, users should review operational impact, b
Before applying updates in production ICS/OT environments, users should review operational impact, backup relevant configurations, test updates in a non-production environment where feasible, and follow applicable change-management and safety procedures.
Mitigation: For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-20.https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
Mitigation: Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers. Users should u
Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers. Users should upgrade to the fixed version or later as soon as operationally feasible. The fix is available in EC firmware V3.3b64 and CW firmware V3.3b26. Contact your Johnson Controls representative or authorized EasyIO distributor.

// References