CISA has published ICS Advisory ICSA-26-279-01 covering two vulnerabilities in Johnson Controls' EasyIO FG series controllers — devices that sit at the heart of building automation and operational technology environments across critical manufacturing, commercial facilities, government facilities, transportation systems, and energy sector deployments worldwide. The advisory is blunt about the impact: successful exploitation could allow an attacker to gain full unauthorized access to the device.
For defenders running smart buildings, campuses, hospitals, airports, or industrial facilities, this is not a theoretical concern. EasyIO FG controllers are IP-connected, Niagara/Sedona-framework-based field controllers frequently reachable on flat OT networks, and the two flaw classes named in this advisory — Use of Hard-coded Credentials (CWE-798) and Improper Privilege Management (CWE-269) — are the exact combination that turns a network-reachable controller into a persistent beachhead inside a facilities network.
If you operate EasyIO FG hardware at firmware version 2.0b52 or earlier, treat this as an active remediation priority, not a backlog item.
Technical Analysis
Affected Products and Versions
| Product | Affected Versions | CVEs | CVSS v3 |
|---|---|---|---|
| Johnson Controls EasyIO FG firmware | <= 2.0b52 | CVE-2026-27872, CVE-2026-27873 | 7.7 (High) |
The EasyIO FG series (including FG-32+, FW, and FS variants in the field) is deployed globally across multiple critical infrastructure sectors. These controllers expose a web-based management interface, BACnet/IP services (UDP 47808), and often FTP and SSH for engineering and maintenance workflows.
CVE-2026-27872 — Hard-Coded Credentials (CWE-798)
The advisory indicates that the EasyIO FG firmware contains credentials embedded in the firmware itself. From a defender's perspective, the attack chain here is depressingly simple:
- Reconnaissance: The attacker identifies EasyIO FG controllers via network scanning — these devices fingerprint easily via their web interface banners, BACnet device objects, and default service exposure.
- Credential extraction or reuse: Hard-coded credentials can be extracted from firmware images (which may be downloadable or present on engineering workstations) or simply enumerated once published. Once one device's credentials are known, they typically work across the entire fleet — this is the defining danger of CWE-798.
- Authentication: The attacker authenticates to the device's management services (web UI, SSH, or FTP) using the embedded credentials.
- Compromise: Combined with CVE-2026-27873, access escalates beyond a restricted service account to full device control.
CVE-2026-27873 — Improper Privilege Management (CWE-269)
This second flaw means that the account or session obtained via the hard-coded credentials is not properly constrained. An attacker who authenticates — even through what should be a limited interface — can obtain privileges beyond what the role design intended, up to full administrative control of the controller. In practical terms, that means:
- Modifying or replacing control logic (Sedona wire sheets / control programs)
- Changing setpoints, schedules, and physical outputs (HVAC, access-adjacent systems, environmental controls)
- Altering network configuration, enabling/disabling services, or flashing modified firmware
- Using the device as a pivot point into adjacent OT and IT segments
Why the Combined Score Matters
A CVSS v3 base score of 7.7 reflects a network-exploitable issue with high impact on confidentiality, integrity, and availability. In OT environments, the integrity and availability impact is the real story: an attacker with full control of a field controller can manipulate physical processes, and detection in OT environments is typically far weaker than in IT. Dwell times measured in months are common.
Exploitation Status
At publication, CISA reports no confirmed public exploitation specifically attributed to these CVEs. However, two factors should drive urgency regardless:
- Hard-coded credential vulnerabilities in ICS products historically transition from disclosure to exploitation quickly — credential material, once known, requires zero exploit development skill to use.
- Internet-exposed building automation controllers are routinely discovered and cataloged by scanning services. Any EasyIO FG device reachable from the internet or from a compromised IT segment should be considered at immediate risk.
Check the CISA Known Exploited Vulnerabilities catalog regularly; ICS CVEs with this profile are KEV candidates.
Detection & Response
This is a technical ICS threat. The detections below target the observable behaviors an attacker would generate when discovering, authenticating to, and manipulating EasyIO FG controllers. Because these controllers are typically not EDR-covered endpoints, detection leans on network telemetry, firewall/IDS logs, and syslog ingestion into your SIEM — which should already be standard practice for your OT DMZ and building automation VLANs.
Sigma Rules
---
title: Repeated Authentication Attempts to EasyIO FG Controller Management Interface
id: 3f9c2e81-7b44-4d5a-9e1f-8a2c4d6b0f31
status: experimental
description: Detects high-frequency authentication attempts against Johnson Controls EasyIO FG controller web management interfaces, consistent with hard-coded credential testing or brute-force activity following ICSA-26-279-01 disclosure.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-01
- https://attack.mitre.org/techniques/T1078/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.initial_access
- attack.t1078
- cve.2026-27872
logsource:
category: webserver
product: zeek
detection:
selection:
uri_path|contains:
- '/login'
- '/auth'
- '/sedona'
status_code:
- 401
- 403
timeframe: 5m
condition: selection | count() by src_ip > 10
falsepositives:
- Misconfigured engineering workstations polling controllers
- Legitimate Niagara supervisor reconnection storms after network blips
level: high
---
title: Network Connection to EasyIO FG Management Services from Outside OT VLAN
id: 8d1e4a72-3c65-4f2b-b7d9-5e6a1c8f2b44
status: experimental
description: Detects connections from non-OT source networks to EasyIO FG controller management ports (HTTP/HTTPS/SSH/FTP). Building automation controllers should only accept management sessions from engineering workstations or the Niagara supervisor segment.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-01
- https://attack.mitre.org/techniques/T0859/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.lateral_movement
- attack.t1021
- cve.2026-27873
logsource:
category: firewall
detection:
selection_dst_port:
dst_port:
- 22
- 21
- 80
- 443
- 5011
filter_legit_ot:
src_ip|cidr:
- '10.10.0.0/16' # REPLACE with your OT/engineering VLAN range
condition: selection_dst_port and not filter_legit_ot
falsepositives:
- Authorized remote vendor maintenance (should be tunneled and documented)
- Recently deployed controllers not yet added to the management ACL
level: high
---
title: BACnet WriteProperty Activity Targeting EasyIO FG Controllers
id: c4a7d910-2e58-4b13-9f66-1d3b5e7a8c22
status: experimental
description: Detects BACnet WriteProperty service requests from hosts that are not the designated building automation supervisor. Unauthorized write activity on EasyIO FG controllers may indicate manipulation of control logic or setpoints following credential compromise.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-01
- https://attack.mitre.org/techniques/T0855/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.ics
- attack.t0855
logsource:
category: network_connection
product: zeek
detection:
selection:
dst_port: 47808
proto: udp
filter_supervisor:
src_ip|cidr:
- '10.10.5.10/32' # REPLACE with your BAS/Niagara supervisor IP
condition: selection and not filter_supervisor
falsepositives:
- Commissioning tools during authorized engineering work
- Secondary supervisor or analytics platform not yet whitelisted
level: medium
KQL — Microsoft Sentinel
This query hunts CommonSecurityLog (firewall/NGFW syslog) and Syslog telemetry for connections to EasyIO FG management services from outside your authorized OT management range. Update the CIDR values and device subnet to match your environment, and ensure your OT network sensors and firewalls are forwarding to Sentinel via a CEF collector.
// Hunt: Unauthorized connections to EasyIO FG controller management services
// Reference: CISA ICSA-26-279-01 (CVE-2026-27872, CVE-2026-27873)
let EasyIOSubnets = dynamic(["10.20.0.0/16", "192.168.50.0/24"]); // REPLACE: your BAS/OT controller subnets
let AuthorizedMgmt = dynamic(["10.10.5.0/24"]); // REPLACE: engineering workstation / supervisor range
let MgmtPorts = dynamic([22, 21, 80, 443, 5011, 47808]);
CommonSecurityLog
| where TimeGenerated > ago(7d)
| where DestinationPort in (MgmtPorts)
| where ipv4_is_in_range(DestinationIP, EasyIOSubnets[0]) or ipv4_is_in_range(DestinationIP, EasyIOSubnets[1])
| where not(ipv4_is_in_range(SourceIP, AuthorizedMgmt[0]))
| where DeviceAction !in ("deny", "drop", "blocked", "Deny")
| summarize ConnectionCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
Ports = make_set(DestinationPort), Actions = make_set(DeviceAction)
by SourceIP, DestinationIP, DeviceVendor, DeviceProduct
| extend RiskNote = case(
ConnectionCount > 50, "High volume - possible credential testing against hard-coded creds (CVE-2026-27872)",
array_length(Ports) > 2, "Multi-service probing - reconnaissance behavior",
"Single connection - verify against change tickets")
| sort by ConnectionCount desc;
A companion query for hunting authentication failure patterns in syslog if your controllers or intermediate gateways forward auth logs:
// Hunt: Authentication failure bursts against EasyIO FG controllers
// Reference: CVE-2026-27872 (hard-coded credentials)
Syslog
| where TimeGenerated > ago(24h)
| where SyslogMessage has_any ("EasyIO", "sedona", "FG-32", "authentication failure", "login failed", "invalid user")
| summarize FailedAttempts = count(), SampleMessages = make_set(SyslogMessage, 3)
by Computer, HostIP, bin(TimeGenerated, 5m)
| where FailedAttempts >= 5
| sort by FailedAttempts desc;
Velociraptor VQL
EasyIO FG controllers themselves are embedded Linux devices typically outside Velociraptor's coverage, but engineering workstations are prime targets — an attacker seeking the hard-coded credentials or offline firmware images will look there first. This artifact hunts Windows engineering workstations for suspicious access to EasyIO firmware files, configuration backups, and credential storage, plus outbound connections to controller subnets.
-- Hunt engineering workstations for EasyIO FG firmware/credential access and controller connections
-- Reference: CISA ICSA-26-279-01 (CVE-2026-27872, CVE-2026-27873)
-- Section 1: Recently modified firmware or config files for EasyIO tooling
SELECT FullPath, Size, Mtime, Atime
FROM glob(globs=[
'C:/Users/*/Downloads/*easyio*',
'C:/Users/*/Downloads/*EasyIO*',
'C:/Users/*/Desktop/**/*.kit',
'C:/Users/*/**/*.sedona',
'C:/Program Files*/EasyIO/**/*'
])
WHERE Mtime > now() - 604800
-- Section 2: Processes with live connections to typical EasyIO management ports
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(easyio|sedona|niagara|47808)'
OR Exe =~ '(?i)(easyio|sedona)'
For network connection state on those workstations:
-- Outbound connections from endpoints to EasyIO management ports
SELECT Pid, Name, Path, Status, Family, Type,
Laddr.IP AS LocalIP, Laddr.Port AS LocalPort,
Raddr.IP AS RemoteIP, Raddr.Port AS RemotePort
FROM netstat()
WHERE RemotePort IN (22, 21, 80, 443, 5011, 47808)
AND Status = 'ESTABLISHED'
AND RemoteIP =~ '^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.)'
Remediation / Verification Script
This Bash script is intended to run from a Linux jump host or OT security sensor with reachability to your controller subnet. It performs three jobs: (1) discovery of EasyIO FG devices via BACnet Who-Is and HTTP banner probing, (2) firmware version retrieval where the device's web interface exposes it, and (3) flagging any device at or below firmware 2.0b52 as vulnerable. Run it read-only against a target subnet list — never run active scans against production OT without change approval.
#!/usr/bin/env bash
# EasyIO FG Exposure & Firmware Audit — ICSA-26-279-01
# CVE-2026-27872 / CVE-2026-27873
# Run from an authorized OT jump host. Read-only checks only.
TARGETS_FILE="easyio_targets.txt" # One controller IP per line
REPORT="easyio_audit_$(date +%Y%m%d_%H%M).csv"
VULN_THRESHOLD="2.0b52"
echo "ip,http_reachable,ssh_reachable,bacnet_responsive,firmware,vulnerable" > "$REPORT"
while read -r IP; do
[ -z "$IP" ] && continue
# Check web management interface (banner often identifies EasyIO FG)
HTTP="no"; FW="unknown"
BANNER=$(curl -sk --max-time 5 "http://${IP}/" 2>/dev/null | head -c 2000)
if echo "$BANNER" | grep -qiE "easyio|sedona"; then
HTTP="yes"
# Attempt to extract firmware/version string from common status pages
FW=$(curl -sk --max-time 5 "http://${IP}/platform" 2>/dev/null \
| grep -oiE "2\.0b[0-9]+" | head -1)
[ -z "$FW" ] && FW=$(echo "$BANNER" | grep -oiE "2\.0b[0-9]+" | head -1)
[ -z "$FW" ] && FW="unknown"
fi
# Check SSH exposure
SSH="no"
timeout 3 bash -c "echo > /dev/tcp/${IP}/22" 2>/dev/null && SSH="yes"
# Check BACnet/IP responsiveness (requires nmap BACnet script or bacnet tools)
BACNET="no"
nmap -sU -p 47808 --script bacnet-info --max-retries 1 --host-timeout 8s "$IP" 2>/dev/null \
| grep -qi "BACnet" && BACNET="yes"
# Vulnerability determination: <= 2.0b52 is affected
VULN="unknown"
if [ "$FW" != "unknown" ]; then
N=$(echo "$FW" | grep -oE "[0-9]+")
if [ "$N" -le 52 ]; then VULN="YES - PATCH NOW"; else VULN="no"; fi
fi
echo "${IP},${HTTP},${SSH},${BACNET},${FW},${VULN}" | tee -a "$REPORT"
done < "$TARGETS_FILE"
echo ""
echo "=== Audit complete: $REPORT ==="
echo "Devices flagged 'YES - PATCH NOW' must be updated per Johnson Controls advisory ICSA-26-279-01"
grep "YES - PATCH NOW" "$REPORT" | cut -d',' -f1 | while read -r VIP; do
echo "REMINDER: Verify $VIP is NOT internet-reachable: https://www.shodan.io/search?query=${VIP}"
done
Operationalize the output: import the CSV into your asset inventory and CMDB, open change tickets for every YES - PATCH NOW device, and feed the discovered IP list back into the Sentinel CIDR ranges used by the KQL hunt above.
Remediation
1. Patch Immediately
- Upgrade all EasyIO FG controllers running firmware <= 2.0b52 to the fixed firmware release referenced in the Johnson Controls product security advisory accompanying ICSA-26-279-01. Contact Johnson Controls Product Security or your authorized distributor to obtain the updated firmware package — EasyIO firmware updates are distributed through the vendor channel and the EasyIO FTP/partner portal.
- Because CVE-2026-27872 involves hard-coded credentials, patching alone may not be sufficient if the credential material was embedded in prior firmware and is now publicly known. After upgrading, verify that the embedded account has been removed or that its credentials have been rotated by the new firmware. Where the device permits, change all local account passwords post-upgrade.
2. Network Segmentation (Do This Regardless of Patch Status)
- Isolate building automation controllers on dedicated VLANs with no direct internet access. This is a CISA standard recommendation for all ICS assets and is the single highest-value compensating control for hard-coded credential flaws.
- Enforce a default-deny ACL permitting controller management traffic (ports 22, 80/443, 5011) only from designated engineering workstations and the Niagara/BAS supervisor.
- Restrict BACnet/IP (UDP 47808) to the OT segment; block BACnet broadcast traffic from crossing into IT networks.
- Confirm via Shodan/Censys search that none of your controllers are internet-indexed. If any are, treat them as compromised until proven otherwise — rotate credentials, audit control logic, and review logs.
3. Compromise Assessment for Exposed Devices
For any controller that was internet-reachable or reachable from an untrusted segment before patching:
- Audit the Sedona application/wire sheet against a known-good backup for unauthorized logic changes.
- Review setpoints, schedules, and network configuration for unauthorized modifications.
- Check for added local user accounts, enabled services (FTP/Telnet) that were not previously active, and modified startup configurations.
- If integrity cannot be verified, reflash the device with known-good firmware and restore the application from a trusted backup.
4. Credential Hygiene
- Change all device credentials — not just the administrative account — following the firmware upgrade.
- Disable any services not required for operations (FTP and Telnet are frequent offenders on these controllers; prefer SFTP/SSH where supported).
- Where the platform supports it, integrate controller authentication with centralized management and logging so auth events are visible in your SIEM.
5. Monitoring and Detection
- Deploy the Sigma rules and Sentinel queries from this post against your OT DMZ firewall and sensor telemetry.
- Ensure BACnet WriteProperty and controller management sessions are logged and alerting on non-supervisor sources.
- Subscribe to CISA ICS advisories and monitor the CISA KEV catalog for addition of CVE-2026-27872 or CVE-2026-27873.
6. Reporting
CISA encourages organizations to report suspected malicious activity related to this advisory through the CISA incident reporting portal. Document your remediation timeline — for organizations subject to NERC CIP, TSA pipeline/rail directives, HIPAA (healthcare facilities), or CMMC (defense industrial base facilities), this advisory response belongs in your compliance evidence trail.
Bottom Line
Hard-coded credentials plus improper privilege management is the worst pairing an ICS defender can face: it eliminates the attacker's need for exploit sophistication entirely. The EasyIO FG fleet in your facilities is only as safe as your segmentation and your patching cadence. Inventory your controllers this week, verify firmware versions, patch anything at or below 2.0b52, and confirm nothing is reachable from the internet. If you find exposure, assume compromise and validate device integrity before returning it to service.
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.