high · CVSS v3 7.5 · CVSS v4 7.3
CVE-2026-64893
Johnson Controls EasyIO NEO devices before version 3.3b25 transmit sensitive data in cleartext, enabling a Man‑In‑The‑Middle attack. The fla
Overview
Johnson Controls EasyIO NEO devices before version 3.3b25 transmit sensitive data in cleartext, enabling a Man‑In‑The‑Middle attack. The flaw exposes credentials and configuration information to anyone on the same network. It is rated high severity with a CVSS v3 score of 7.5.
Description
- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.
Impact
The vulnerability compromises confidentiality by allowing attackers to intercept and read sensitive data. Integrity is also at risk if attackers modify traffic. Availability is not directly impacted, but the exposure can lead to further attacks. Defenders must protect network segments and monitor for unauthorized traffic.
Remediation
Upgrade EasyIO NEO firmware to version 3.3b25 or later. If upgrade is not possible, enforce TLS or VPN for all communication, block unencrypted traffic with firewall rules, and segment the device on a dedicated VLAN. Regularly audit device logs for anomalous connections.
Risk context
High severity (CVSS 7.5) and lack of EPSS data suggest a moderate to high risk for exposed networks. Immediate patching or mitigation is recommended to prevent potential data leakage.
Affected products
- Johnson Controls EasyIO NEO
Scores
- Severity
- high
- CVSS v2
- 5
- CVSS v3
- 7.5
- CVSS v4
- 7.3
- EPSS
- —