rootpwn

high · CVSS v3 7.5 · CVSS v4 7.3

CVE-2026-64893

Johnson Controls EasyIO NEO devices before version 3.3b25 transmit sensitive data in cleartext, enabling a Man‑In‑The‑Middle attack. The fla

Overview

Johnson Controls EasyIO NEO devices before version 3.3b25 transmit sensitive data in cleartext, enabling a Man‑In‑The‑Middle attack. The flaw exposes credentials and configuration information to anyone on the same network. It is rated high severity with a CVSS v3 score of 7.5.

Description

- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.

Impact

The vulnerability compromises confidentiality by allowing attackers to intercept and read sensitive data. Integrity is also at risk if attackers modify traffic. Availability is not directly impacted, but the exposure can lead to further attacks. Defenders must protect network segments and monitor for unauthorized traffic.

Remediation

Upgrade EasyIO NEO firmware to version 3.3b25 or later. If upgrade is not possible, enforce TLS or VPN for all communication, block unencrypted traffic with firewall rules, and segment the device on a dedicated VLAN. Regularly audit device logs for anomalous connections.

Risk context

High severity (CVSS 7.5) and lack of EPSS data suggest a moderate to high risk for exposed networks. Immediate patching or mitigation is recommended to prevent potential data leakage.

Affected products

  • Johnson Controls EasyIO NEO

Scores

Severity
high
CVSS v2
5
CVSS v3
7.5
CVSS v4
7.3
EPSS
—

cleartext MITM network-security firmware-patch JohnsonControls

← All CVEs