Impact
The vulnerability allows an unauthorized party to collect data from common resource locations on Johnson Controls Easy IO Neo devices. The disclosed weakness corresponds to CWE-200, which describes inadvertent disclosure of information that should remain confidential. No explicit mention of privileges or user interaction is provided in the CVE data, but the description indicates that data can be retrieved without stipulated authentication. The impact is a loss of confidentiality for any information exposed through these resource locations.
Affected Systems
Johnson Controls Easy IO Neo firmware versions prior to 3.3b63 are affected. Devices running any release before 3.3b63 expose the vulnerable data paths; newer firmware releases implement mitigations that eliminate the exposure.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, implying that there is no widespread or confirmed exploitation. Attackers who can reach the affected device may read exposed resources, leading to confidentiality loss. The specific attack vector is inferred to involve accessing the device’s exposed data interfaces, but the CVE data does not specify required privileged access or user interaction.
OpenCVE Enrichment