Impact
Johnson Controls EasyIO NEO has a Cleartext Transmission of Sensitive Information flaw that allows an attacker to intercept traffic and capture confidential data. The vulnerability enables a Man‑in‑the‑Middle attack, potentially exposing credentials, configuration details, or other sensitive information transmitted without encryption. This can lead to data breach and compromise of system integrity.
Affected Systems
Johnson Controls EasyIO NEO firmware versions earlier than 3.3b25 are affected. Devices running those firmware releases are vulnerable to cleartext transmission of sensitive information, which can enable a Man‑in‑the‑Middle attack.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV. The attack vector is inferred to be network‑based, with an attacker able to position a Man‑in‑the‑Middle on the communication path and capture cleartext traffic. Given the lack of active exploitation data, the immediate risk remains medium to high but requires mitigation to prevent potential data exposure.
OpenCVE Enrichment