Executive brief
Johnson Controls EasyIO Neo Series controllers are industrial devices used to manage building automation and control systems across critical infrastructure. A vulnerability in these controllers could expose sensitive information that attackers could use to conduct further attacks against the facility's operational technology networks, potentially disrupting manufacturing, energy, or transportation systems.
Technical details
The vulnerability allows exposure of sensitive information to an unauthorized actor on affected EasyIO Neo Series EC and CW Controllers. The vulnerability affects multiple firmware versions (V3.3b24, V3.3b25 for CW; V3.3b62, V3.3b63 for EC). Exploitation may require network access or specific preconditions depending on how the sensitive information is exposed.
Affected products
- Johnson Controls EasyIO Neo Series EC Controllers V3.3b62, V3.3b63
- Johnson Controls EasyIO Neo Series CW Controllers V3.3b24, V3.3b25
Timeline
- 2026-10-01: disclosed
- 2026-10-01: advisory: CISA ICS Advisory ICSA-26-274-04