Johnson Controls Fixes Two EasyIO Neo Controller Security Flaws

Security technician validating backup and recovery for an access control controller

Johnson Controls has released updates for EasyIO Neo controllers after two security issues were documented in separate coordinated advisories. The vulnerabilities concern exposure of sensitive information and transmission of credentials or session information without adequate encryption.

What the two advisories cover

CVE-2026-64892 involves information that can be obtained through physical debugging interfaces. CISA gives it a maximum CVSS v3 base score of 3.5. CVE-2026-64893 addresses cleartext transmission of credentials and session data and carries a maximum CVSS v3 base score of 5.4.

The affected devices are used in building-control environments, where controller credentials can provide a path into operational functions. CISA says it is not aware of public exploitation targeting either issue. Johnson Controls lists the related product advisories JCI-PSA-2026-20 and JCI-PSA-2026-30 on its security-advisory portal.

Updates and compensating controls

The vendor identifies EC version 3.3b64 and CW version 3.3b26 as fixed releases. For the network issue, operators should use HTTPS and disable HTTP where their deployment allows it. Physical access to debugging interfaces should also be restricted, with controller locations monitored as part of the site’s security plan.

Before updating controllers, building operators should document current logic and configuration, confirm a rollback path and schedule functional testing. Network teams should check that management traffic stays on trusted segments. SectechMedia’s industrial safety and monitoring coverage includes further guidance for operational technology estates.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *