Independent tech intelligence, checked against primary sources.

TechPulseMind Useful technology.
No manufactured hype.

Johnson Controls EasyIO Neo Controllers: Patch Fixes Debug-Port Data Leak

Johnson Controls fixed a data-exposure flaw in EasyIO Neo EC and CW controllers. Affected firmware is EC V3.3b63/b62 and CW V3.3b25/b24; update to EC V3.3b64 or CW V3.3b26.

Johnson Controls EasyIO Neo Controllers: Patch Fixes Debug-Port Data Leak

Johnson Controls has released firmware updates for its EasyIO Neo Series EC and CW controllers to close a vulnerability that could let an attacker reach sensitive information on the devices. CISA published the advisory, ICSA-26-274-04, on October 1, 2026, describing the flaw as CVE-2026-64892.

The affected firmware versions are EC V3.3b63 and V3.3b62, and CW V3.3b25 and V3.3b24. The fix arrives in EC firmware V3.3b64 and CW firmware V3.3b26, according to the advisory.

What the flaw allows

According to the advisory, successful exploitation could give an attacker access to sensitive information that could then be used to conduct further attacks against the system. The issue is classified as CWE-200, exposure of sensitive information to an unauthorized actor.

Severity is rated differently depending on the scoring system: CVSS 3.1 gives it a base score of 3.5, or low, while CVSS 4.0 puts it at 4.8, or medium. The EC and CW are programmable edge controllers built for building automation, handling functions such as HVAC, lighting and energy management, and supporting BACnet and Modbus.

The advisory lists deployment across critical manufacturing, commercial facilities, government services and facilities, transportation systems, and energy, with devices in use worldwide. Johnson Controls is headquartered in Ireland. Gabriele Gardois reported the vulnerability to the company, and CISA says no known public exploitation specifically targeting it has been reported at this time.

How to update

Johnson Controls advises users to upgrade to the fixed version or later as soon as operationally feasible, and to contact a Johnson Controls representative or authorized EasyIO distributor. Before applying updates in production ICS/OT environments, the advisory says to review operational impact, back up relevant configurations, test in a non-production environment where feasible, and follow change-management and safety procedures.

If an immediate update is not possible, the company recommends physical access controls to keep unauthorized people away from device debug ports, monitoring network traffic to and from affected devices for unusual access attempts, applying least privilege to accounts and services that interact with the devices, using firmware updates that disable debug interfaces or require authentication for debug access where possible, and deploying intrusion detection or prevention systems. The advisory notes these measures reduce risk but may not fully remediate the vulnerability.

More detailed instructions are in Johnson Controls Product Security Advisory JCI-PSA-2026-20, available through the company’s Trust Center cybersecurity security-advisories page.

Sources

Some links on this page may be affiliate links. If you buy through them we may earn a commission at no extra cost to you. See our affiliate disclosure.