Description
- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force).

This issue affects Easy IO FG: before 2.0b52.
Published: 2026-10-01
Score: 5.6 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation via Brute Force
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an Improper Privilege Management flaw in Johnson Controls Easy IO FG, allowing attackers to brute force credentials. An attacker who obtains valid credentials or guesses them can gain unauthorized privileged access, compromising the confidentiality, integrity, and availability of the system. The primary impact is the potential for an attacker to elevate access rights and perform unauthorized actions within the device. The weakness corresponds to CWE-269.

Affected Systems

Johnson Controls Easy IO FG, versions prior to 2.0b52 are affected by this flaw.

Risk and Exploitability

The CVSS score of 5.6 indicates a moderate risk level. No EPSS score is available, so the historical exploitation probability is unknown, but the flaw has not been reported in the CISA KEV catalog. The exploit likely requires network access to the device or internal network access that would enable brute force attempts against privileged accounts. The attack vector is inferred as Local/Network depending on network segmentation, but the description explicitly states it permits brute force.

Generated by OpenCVE AI on October 1, 2026 at 20:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Easy IO FG to version 2.0b52 or newer to eliminate the privilege management flaw.
  • Enforce strong password policies and enable account lockout or throttling mechanisms to mitigate brute force attempts.
  • Disable or restrict access for unused privileged accounts and monitor authentication logs for suspicious activity.

Generated by OpenCVE AI on October 1, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.
Title EasyIO FG
First Time appeared Johnson Controls
Johnson Controls easy Io Fg
Weaknesses CWE-269
CPEs cpe:2.3:a:johnson_controls:easy_io_fg:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls easy Io Fg
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:P'}


Subscriptions

Johnson Controls Easy Io Fg
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-10-01T21:38:28.271Z

Reserved: 2026-02-24T11:29:18.530Z

Link: CVE-2026-27872

cve-icon Vulnrichment

Updated: 2026-10-01T19:10:46.558Z

cve-icon NVD

Status : Received

Published: 2026-10-01T19:17:20.247

Modified: 2026-10-01T20:17:24.563

Link: CVE-2026-27872

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:45:06Z

Weaknesses
  • CWE-269

    Improper Privilege Management