CVE‑2026‑64892 in Johnson Controls EasyIO Neo EC & CW Controllers Exposes Sensitive Information
What It Is — CISA issued an advisory for a vulnerability (CVE‑2026‑64892) in Johnson Controls EasyIO Neo Series EC and CW programmable edge controllers. The flaw could let an unauthenticated actor retrieve sensitive configuration data that may be leveraged for further attacks on building‑automation networks.
Exploitability — No public exploit code has been released, but the advisory confirms successful exploitation is feasible. CVSS v3.1 base score 3.5 (moderate).
Affected Products — Johnson Controls EasyIO Neo Series:
- EC Controllers V3.3b62, V3.3b63
- CW Controllers V3.3b24, V3.3b25
Why It Matters for Trust & Control Assurance
- Secure Configuration & Patch Management – The issue tests the control objective of maintaining hardened, up‑to‑date OT assets, a core evidence point for audit‑ready programs across frameworks.
- Continuous Asset Visibility – Demonstrates the need for an inventory that feeds into real‑time monitoring, proving due‑diligence to regulators and enterprise buyers.
- Defensible Evidence – A single unpatched controller can erode the trust posture of an entire facility; continuous logging and evidence collection become essential to show control effectiveness.
Recommended Actions
- Inventory all EasyIO Neo EC/CW controllers and confirm firmware versions against the list above.
- Apply Johnson Controls‑provided patches or upgrade to the latest firmware immediately.
- Feed controller inventory and patch status into a continuous control‑monitoring platform.
- Enable detailed logging on each device and forward logs to a centralized SIEM for anomaly detection.
- Conduct a risk assessment of downstream systems that could be compromised using the exposed configuration data.
Source: CISA Advisory