Skip to content

Executive Summary

A vulnerability exists in Johnson Controls EasyIO Neo Series EC and CW Controllers that permits the interception and reading of sensitive information, including credentials and session data, transmitted over the network in cleartext. This vulnerability is tracked under CVE-2026-64893 and affects specific firmware versions of the controllers. The affected products include the EasyIO Neo Series EC Controllers (V3.3b62, V3.3b63) and CW Controllers (V3.3b24, V3.3b25). This issue has implications for critical infrastructure sectors, including manufacturing, commercial facilities, government services, transportation systems, and energy.
Johnson Controls has released fixed firmware versions to remedy the vulnerability, with EC controllers updated to V3.3b64 and CW controllers updated to V3.3b26. As an immediate mitigation, Johnson Controls recommends enabling HTTPS/TLS for all web-based management access, disabling HTTP access entirely, isolating devices on a segmented network, and using VPNs for remote access. Organizations are advised to perform impact analysis before applying updates in operational environments, back up configurations, and follow change management procedures.

Facts Only

* The vulnerability is identified as CVE-2026-64893.
* Affected products are Johnson Controls EasyIO Neo Series EC Controllers (V3.3b62, V3.3b63) and CW Controllers (V3.3b24, V3.3b25).
* The vulnerability allows for the cleartext transmission of sensitive information like credentials and session data over the network.
* The affected systems are programmable building automation edge controllers managing HVAC, lighting, and energy systems.
* Johnson Controls has released fixed versions: EC firmware V3.3b64 and CW firmware V3.3b26.
* Affected sectors include Critical Manufacturing, Commercial Facilities, Government Services/Facilities, Transportation Systems, and Energy.
* The vulnerability is rated with a CVSS Base Score of 5.4 (version 3.1).
* Mitigations include enabling HTTPS/TLS, disabling HTTP access, network segmentation, and using VPNs for remote access.
* The weakness maps to CWE-319: Cleartext Transmission of Sensitive Information.

Full Take

The existence of a cleartext transmission flaw in building automation controllers touches upon a fundamental tension between operational expediency and security posture in critical infrastructure environments. The reported vulnerability is not just a technical flaw; it represents a systemic risk where the convenience of network management protocols allows for data exposure, especially when dealing with physical control systems. The layered mitigations proposed—patching, protocol enforcement (HTTPS), network segmentation, and access restriction—reveal a predictable defensive strategy against cleartext transmission, yet the effectiveness of this strategy hinges entirely on operational reality within high-stakes environments.
The pattern observed is the reliance on external vendor remediation combined with an explicit mandate for in-situ risk assessment before deployment, which highlights a potential friction point between rapid vulnerability response and the necessary bureaucratic processes of operational technology management. The suggestion to move from HTTP to TLS addresses the *mechanism* of the leak, while segmentation addresses the *exposure*. The deeper implication lies in whether organizations prioritize proactive architectural hardening (isolating endpoints) or reactive patching when dealing with complex legacy systems where downtime is heavily weighted against security latency. Who bears the cost of the gap between immediate fix and operational feasibility?
Bridge Questions: If a system operator prioritizes continuity, how can risk assessment frameworks be adapted to quantify the risk introduced by an unpatched control system versus the risk of potential data exposure? What mechanisms could reduce the friction between vulnerability disclosure and mandatory implementation in highly regulated ICS/OT environments? What are the long-term societal consequences when reliance on cleartext communication becomes normalized in energy or transportation systems?

From the original · CISA ICS Advisories

Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data.
Read the full story at cisa.gov

Sentinel — Human

Confidence

This text appears to be a factual summary derived from a vendor security advisory and related regulatory guidance, demonstrating high fidelity to source material rather than synthetic narrative generation.

Signals Detected
low severity: Moderate sentence length variance; structured presentation of technical data suggests human editorial oversight.
low severity: High internal logical flow, moving clearly from vulnerability identification to specific fixes and layered mitigations.
medium severity: Structured presentation of technical details (CVEs, CVSS scores, mitigation steps) typical of official security advisories, suggesting coordination with a vendor or regulatory body.
low severity: Direct citation of specific CVEs, vendor names, and external references (CISA links) suggests grounding in verifiable, official data rather than pure fabrication.
Human Indicators
The inclusion of detailed, multi-layered mitigation strategies, specific product versions, and direct links to official bodies (Johnson Controls Trust Center, CISA) points toward reporting based on specific disclosed information rather than generalized AI synthesis.
Johnson Controls EasyIO Neo Series EC and CW Controllers | Huntaegis