Cleartext Credential Exposure Vulnerability (CVE‑2026‑64893) in Johnson Controls EasyIO Neo Controllers
What It Is — The EasyIO Neo Series EC and CW edge controllers transmit credentials and session data in cleartext over the network. The flaw is tracked as CVE‑2026‑64893 and has a CVSS v3 base score of 5.4 (moderate).
Exploitability — No public exploit has been observed, but the vulnerability is exploitable by any adversary with network access to the controller.
Affected Products — Johnson Controls EasyIO Neo Series EC Controllers V3.3b62, V3.3b63 and CW Controllers V3.3b24, V3.3b25.
Why It Matters for Trust & Control Assurance
- Encryption in transit is a core control that spans multiple frameworks; lacking it leaves a gap in data‑in‑motion protection and audit evidence.
- Continuous monitoring of network traffic and logging of credential use provides the defensible trail auditors expect.
- Demonstrating that this control is enforced (e.g., TLS‑protected APIs) signals to enterprise buyers that the building‑automation supply chain is trustworthy.
Recommended Actions
- Enable TLS or an equivalent encrypted channel on all EasyIO Neo controllers.
- Update firmware to the vendor‑released patch that addresses CVE‑2026‑64893.
- Validate that all management traffic is captured in a centralized log and that logs are retained per your audit policy.
- Map the “encrypted transmission of sensitive data” requirement to your control framework of record and capture remediation evidence.
Source: CISA Advisory – ICSA‑26‑274‑05