[Johnson Controls EasyIO Neo Series EC and CW Controllers]: EasyIO Neo Series CISA Advisories: Affected Versions and Sensitive Information Risks

Close-up view of a green circuit board held by a hand, showcasing technology details.

Which Johnson Controls EasyIO Neo Series EC and CW Controller versions are affected by CVE-2026-64892 and CVE-2026-64893?

Close-up view of a green circuit board held by a hand, showcasing technology details.

CISA’s October 01, 2026 advisories identify specific Johnson Controls EasyIO Neo Series EC and CW Controller versions as affected.

The affected versions

The listed affected versions are:

Product Affected versions
EasyIO Neo Series EC Controllers V3.3b62, V3.3b63
CW Controllers V3.3b24, V3.3b25

CISA lists those same EC and CW controller versions for both CVE-2026-64892 and CVE-2026-64893.

Which issues apply

The advisories describe two separate issues:

  • CVE-2026-64892: sensitive information exposure to an unauthorized actor, CVSS v3 score 3.5
  • CVE-2026-64893: cleartext transmission of sensitive information, with possible interception of credentials and session data, CVSS v3 score 5.4

What to check

If your inventory includes any of the versions above, compare the device details against the official CISA advisories. The advisories identify worldwide deployment and list the company headquarters location as Ireland.

Because advisory pages can be updated, use CISA’s current notices when confirming whether a device remains in scope.

What should operators do if they use EasyIO Neo Series EC Controllers V3.3b62 or V3.3b63, or CW Controllers V3.3b24 or V3.3b25?

A woman reading 'What Would Google Do?' at a desk by a window in a modern office.

If you operate one of the EasyIO Neo Series versions named by CISA, the first step is to confirm whether your controller matches the affected list.

Start with the version check

CISA lists these versions as affected:

  • EasyIO Neo Series EC Controllers V3.3b62 and V3.3b63
  • CW Controllers V3.3b24 and V3.3b25

The listed versions are tied to both CVE-2026-64892 and CVE-2026-64893.

Understand the risk being flagged

CISA describes CVE-2026-64892 as exposure of sensitive information to an unauthorized actor.

CISA describes CVE-2026-64893 as cleartext transmission of sensitive information. The advisory context says credentials and session data could be intercepted.

That means operators should treat the issue as an information-exposure concern, especially where credentials or active session data may be involved.

Where to go next

The provided context does not include a patch version, mitigation command, deadline, or required operational procedure. Use the CISA advisories as the official reference for current vendor and mitigation details before making changes to production systems.

How do CVE-2026-64892 and CVE-2026-64893 differ for EasyIO Neo Series controllers?

CVE-2026-64892 and CVE-2026-64893 affect the same listed EasyIO Neo Series EC and CW Controller versions, but CISA describes different sensitive-information risks.

The short comparison

Item CVE-2026-64892 CVE-2026-64893
Affected EC versions V3.3b62, V3.3b63 V3.3b62, V3.3b63
Affected CW versions V3.3b24, V3.3b25 V3.3b24, V3.3b25
CISA description Sensitive information exposure to an unauthorized actor Cleartext transmission of sensitive information
Specific data mentioned Not specified in the provided context Credentials and session data could be intercepted
CVSS v3 score 3.5 5.4

What the difference means

The first advisory is about unauthorized access to sensitive information. The second is about sensitive information being sent in cleartext, with credentials and session data named as possible intercepted information.

The provided context does not give deeper exploit mechanics or mitigation details for either CVE. For current technical guidance, check the CISA pages directly.

What sensitive information risks are described in the CISA advisories for EasyIO Neo Series controllers?

Hand holding smartphone displaying network analysis in high-tech server environment.

CISA’s EasyIO Neo Series advisories focus on sensitive information risks in specific EC and CW Controller versions.

What information risk is described

CISA identifies two related issues:

  • CVE-2026-64892: sensitive information may be exposed to an unauthorized actor.
  • CVE-2026-64893: sensitive information may be transmitted in cleartext.

For CVE-2026-64893, the context specifically mentions possible interception of credentials and session data.

Which controller versions are involved

The advisories list these versions:

  • EasyIO Neo Series EC Controllers V3.3b62 and V3.3b63
  • CW Controllers V3.3b24 and V3.3b25

CISA lists worldwide deployment and identifies the company headquarters location as Ireland.

What is not confirmed here

The provided context does not say which exact credentials or session data could be exposed, whether exploitation has occurred, or what replacement versions are available.

Because this is operational security information, confirm the latest details in CISA’s advisories before deciding on response steps.

Sources / Learn more

Related reading

Comments

Leave a Reply

[privacy-do-not-sell-link]

Discover more from Trending Issues Daily

Subscribe now to keep reading and get access to the full archive.

Continue reading