As reported by CISA in advisory ICSA-26-274-04, Johnson Controls has disclosed an information disclosure vulnerability (CVE-2026-64892) affecting its EasyIO Neo Series EC and CW controllers — programmable edge devices deployed across building automation systems worldwide. While the CVSS v3 score of 3.5 places this firmly in the low-severity tier, the ICS context demands defenders resist the temptation to deprioritize it.
Why Low Severity Doesn't Mean Low Risk
Information disclosure vulnerabilities in operational technology environments rarely remain endpoints in themselves. In a building automation context, exposed configuration data, credentials, or protocol parameters from an EasyIO controller can provide an attacker the reconnaissance material needed to pivot into the broader BACnet or Modbus control network. The advisory notes affected sectors include Critical Manufacturing, Energy, Transportation Systems, Government Facilities, and Commercial Facilities — environments where even a minor foothold can cascade into physical safety incidents or operational disruption.
The affected controllers sit at the edge of the network, directly interfacing with HVAC, lighting, and energy management systems. If an attacker harvests sensitive information from one of these devices, they gain visibility into the control plane architecture — potentially identifying upstream BAS controllers, communication paths, and authentication mechanisms that may be far more valuable than the initial disclosure suggests.
Vulnerability Details
| Field | Value |
|---|---|
| CVE | CVE-2026-64892 |
| CVSS v3 | 3.5 (Low) |
| Vendor | Johnson Controls (HQ: Ireland) |
| Product | EasyIO Neo Series EC and CW Controllers |
| Affected Versions | EC V3.3b62, V3.3b63; CW V3.3b24, V3.3b25 |
| Fixed Versions | EC firmware V3.3b64; CW firmware V3.3b26 |
| Active Exploitation | Not reported in the wild at time of disclosure |
| Deployment | Worldwide across multiple critical infrastructure sectors |
Who Is Most Exposed
Facilities management teams running Johnson Controls EasyIO Neo Series controllers in large commercial buildings, government campuses, manufacturing plants, or energy infrastructure are the primary at-risk population. Organizations with large, heterogeneous building automation deployments — where inventory accuracy is often lacking and firmware versions are inconsistently tracked — face the greatest challenge in identifying and remediating affected devices. Many of these controllers operate in environments with minimal network segmentation between IT and OT, making lateral movement from exposed credentials a realistic threat.
The real risk isn't this single CVE — it's the pattern: edge controllers in building automation systems consistently expose information because they were designed for functionality first and security second. Defenders need to treat every OT information disclosure as a potential privilege escalation vector.
Shield53 Recommendations
- Patch immediately: Upgrade EC controllers to firmware V3.3b64 or later and CW controllers to V3.3b26 or later. Contact your Johnson Controls representative or authorized EasyIO distributor if firmware is not directly accessible.
- Inventory and validate: Conduct a comprehensive scan of all building automation controllers to identify any EasyIO Neo Series devices running affected firmware versions. Discrepancies between documented and actual firmware are common in OT environments — verify, don't assume.
- Segment OT networks: Ensure EasyIO controllers operate on isolated VLANs separate from corporate IT infrastructure. Implement ICS-awarefirewall rules restricting lateral communication between edge controllers and upstream management systems.
- Audit exposed services: Review what management interfaces (web UIs, SSH, Telnet, BACnet ports) are exposed on these controllers. Disable unnecessary services and enforce authentication on all remaining access paths.
- Monitor for exploitation indicators: Deploy network-level detection for anomalous access patterns to EasyIO controller management interfaces, particularly repeated unauthorized access attempts that may indicate credential harvesting.
- Test before deployment: Per CISA guidance, validate firmware updates in a non-production environment before applying to live OT systems. Building automation downtime has real-world operational and safety implications.
This advisory is a reminder that in the converging IT/OT landscape, even low-severity vulnerabilities deserve systematic attention. The gap between a 3.5 CVSS information disclosure and a facility-wide compromise is often measured in the number of unsegmented hops an attacker can traverse — and in poorly architected BAS deployments, that number is frequently zero.