Description
- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.

This issue affects EasyIO NEO: before 3.3b25.
Published: 2026-10-01
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Data exposure via Man‑in‑the‑Middle attack
Action: Patch
AI Analysis

Impact

Johnson Controls EasyIO NEO has a Cleartext Transmission of Sensitive Information flaw that allows an attacker to intercept traffic and capture confidential data. The vulnerability enables a Man‑in‑the‑Middle attack, potentially exposing credentials, configuration details, or other sensitive information transmitted without encryption. This can lead to data breach and compromise of system integrity.

Affected Systems

Johnson Controls EasyIO NEO firmware versions earlier than 3.3b25 are affected. Devices running those firmware releases are vulnerable to cleartext transmission of sensitive information, which can enable a Man‑in‑the‑Middle attack.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV. The attack vector is inferred to be network‑based, with an attacker able to position a Man‑in‑the‑Middle on the communication path and capture cleartext traffic. Given the lack of active exploitation data, the immediate risk remains medium to high but requires mitigation to prevent potential data exposure.

Generated by OpenCVE AI on October 1, 2026 at 23:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade EasyIO NEO firmware to version 3.3b25 or later
  • Configure the device to enforce encrypted communication (enable TLS/SSL) for all management and data channels
  • Place the device behind a firewall or in a segmented network that isolates management interfaces to limit external exposure

Generated by OpenCVE AI on October 1, 2026 at 23:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 23:45:00 +0000

Type Values Removed Values Added
Title Cleartext Transmission of Sensitive Information in Johnson Controls EasyIO NEO Enabling Man‑in‑the‑Middle Attacks

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description - Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.
First Time appeared Johnson Controls
Johnson Controls easyio Neo
Weaknesses CWE-319
CPEs cpe:2.3:a:johnson_controls:easyio_neo:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls easyio Neo
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H'}


Subscriptions

Johnson Controls Easyio Neo
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-10-01T21:25:26.090Z

Reserved: 2026-07-20T19:51:19.089Z

Link: CVE-2026-64893

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:04.540

Modified: 2026-10-01T22:17:04.540

Link: CVE-2026-64893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T00:15:14Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information