Impact
An attacker can take advantage of hard‑coded credentials in Johnson Controls EasyIO FG. The use of fixed passwords permits password‑spraying attacks, enabling an adversary to guess or iterate passwords until successful authentication. Successful exploitation can lead to unauthorized control over the device, compromise of configuration data, and potential lateral movement within the associated environment. The weakness is classified as CWE-798, Hard‑coded Credentials.
Affected Systems
Johnson Controls EasyIO FG firmware versions older than 2.0b52 are affected. The vulnerability is present only in releases before 2.0b52, and no later firmware versions are known to contain the issue.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity. The EPSS score is not available, and the vulnerability has not been listed in the CISA KEV catalog. Attackers are likely to target the device over the network since hard‑coded credentials are accessible via management interfaces, though the exact vector is not explicitly specified in the advisory. Given the moderate score and lack of publicly known exploits, the overall risk is moderate but should be addressed promptly.
OpenCVE Enrichment