CISA advisory ICSA-26-274-04 and the referenced CSAF identify CVE-2026-64892 in Johnson Controls EasyIO Neo Series EC and CW controllers. The issue is classified as Exposure of Sensitive Information to an Unauthorized Actor, with a CVSS v3 base score of 3.5. Affected versions called out in the advisory are EasyIO Neo Series EC Controllers V3.3b63 and V3.3b62, and EasyIO Neo Series CW Controllers V3.3b25 and V3.3b24. The impacted sectors are Critical Manufacturing and Commercial Facilities, which tracks with where these controllers typically live: building automation, plant utilities, and operational technology environments that are assumed to be reachable only by trusted engineering systems.
The score is low on paper, but defenders should not treat this as background noise. In OT and BAS environments, seemingly minor information exposure is often the reconnaissance payload that enables the next step: credential harvesting, controller mapping, protocol abuse, unsafe configuration downloads, or targeted manipulation of setpoints and schedules. The correct posture is urgent verification and containment, not panic.
Technical Analysis
Affected products and versions
- Johnson Controls EasyIO Neo Series EC Controllers V3.3b63 — CVE-2026-64892
- Johnson Controls EasyIO Neo Series EC Controllers V3.3b62 — CVE-2026-64892
- Johnson Controls EasyIO Neo Series CW Controllers V3.3b25 — CVE-2026-64892
- Johnson Controls EasyIO Neo Series CW Controllers V3.3b24 — CVE-2026-64892
Vulnerability class and defensive interpretation
- CVE: CVE-2026-64892
- CVSS: v3 3.5; vector details were not included in the provided summary and should be confirmed against the CSAF/v advisory before final risk scoring.
- Weakness: Exposure of Sensitive Information to an Unauthorized Actor.
- Likely defensive concern: an attacker able to reach the affected controller service or management function may obtain data that should require authorization. In controller ecosystems, sensitive information commonly includes configuration metadata, device identity, network topology hints, credential material or credential-adjacent data, firmware details, point mappings, schedules, users, or diagnostic output. Treat any disclosure as useful pre-attack intelligence even if the CVE itself does not directly grant control.
Exploitation requirements and attack chain from a defender's perspective
- Reachability: the attacker needs network or application-layer access to the affected controller, an exposed management path, or a compromised engineering workstation/jump host that already has that access.
- Trigger: the attacker invokes the vulnerable function or endpoint associated with the information exposure.
- Collection: returned data is harvested and correlated with other building systems, active directory, remote access paths, and vendor documentation.
- Follow-on: the exposed information is used to authenticate elsewhere, identify firmware/protocol behavior, craft valid requests, prioritize higher-value controllers, or support social engineering against facilities and OT staff.
Exploitation status The provided advisory summary does not state a public proof of concept, confirmed active exploitation, or CISA Known Exploited Vulnerabilities inclusion. Do not assume absence of exploitation; assume quiet reconnaissance is possible wherever these devices are reachable from user networks, vendor remote access paths, or flat OT segments. Verify current KEV status and vendor CSAF text during change review.
Detection & Response
The highest-value detections are asset-aware. Generic alerts for controller traffic will drown a SOC. Enrich first: maintain an authoritative inventory of EasyIO Neo EC/CW hosts, firmware versions, approved engineering workstations, vendor jump hosts, BAS servers, and allowed management sources. Then alert on deviations.
---
title: EasyIO Neo Controller Configuration or Backup Access by Non-Engineering Process
id: 9d2c6a1e-5f4b-4c91-a0e2-cve202664892001
status: experimental
description: Detects creation or access of files that look like EasyIO/Neo controller exports, backups, configs, or diagnostics by processes outside expected engineering tooling. Tune paths and approved tool list to the environment before broad deployment.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-04
author: Security Arsenal
date: 2026/10/01
tags:
- attack.collection
- attack.t1005
- attack.reconnaissance
- attack.t1592
logsource:
category: file_event
product: windows
detection:
selection_names:
TargetFilename|contains:
- 'easyio'
- 'neo series'
- 'neoseries'
- 'controller backup'
- 'controller config'
selection_ext:
TargetFilename|endswith:
- '.bak'
- '.backup'
- '.cfg'
- '.config'
- '.zip'
- '.7z'
- '.csv'
- '.log'
filter_tools:
Image|endswith:
- '\approved_engineering_tool.exe'
- '\approved_bas_client.exe'
filter_users:
User|contains:
- 'BAS-ENG-'
- 'OT-JUMP-'
condition: selection_names and selection_ext and not filter_tools and not filter_users
falsepositives:
- Legitimate controller backup jobs, commissioning activity, facilities exports, and vendor maintenance
- Rename or path conventions that coincidentally include product terms
level: medium
---
title: Unexpected Host Communicating with EasyIO Neo Controller Naming Pattern
id: 7b1f8d44-2a6c-4e58-b317-cve202664892002
status: experimental
description: Flags Windows process network connections to hosts whose names indicate EasyIO EC/CW controllers where the initiating process is not an approved BAS or engineering application. Requires a controlled approved-image list and accurate controller naming to remain useful.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-04
author: Security Arsenal
date: 2026/10/01
tags:
- attack.command_and_control
- attack.t1071
- attack.lateral_movement
- attack.t1021
logsource:
category: network_connection
product: windows
detection:
selection_dst:
DestinationHostname|contains:
- 'easyio'
- 'neo-ec'
- 'neo-cw'
- 'bms-ec'
- 'bms-cw'
filter_process:
Image|endswith:
- '\approved_bas_server_service.exe'
- '\approved_engineering_tool.exe'
- '\scomagent.exe'
- '\nessusd.exe'
filter_src:
SourceHostname|startswith:
- 'OT-JUMP-'
- 'BAS-APP-'
- 'BAS-ENG-'
condition: selection_dst and not filter_process and not filter_src
falsepositives:
- Discovery scanners, asset inventory tools, printer/UPS naming collisions, and temporary vendor laptops
level: high
// Asset-aware hunt for access to EasyIO Neo EC/CW controllers from unapproved sources.
// Prerequisites: ingest firewall/NDR as CommonSecurityLog, controller/syslog as Syslog, and maintain watchlists.
let AffectedVersions = dynamic(['V3.3b63','V3.3b62','V3.3b25','V3.3b24']);
let ControllerTerms = dynamic(['easyio','neo series','neoseries','neo-ec','neo-cw','johnson controls']);
let ApprovedSources = toscalar(externaldata(SourceIP:string, Note:string)[h'https://contoso.invalid/approved_bms_sources.csv'] with(format='csv', ignoreFirstRecord=true) | project SourceIP);
let FW =
CommonSecurityLog
| where TimeGenerated > ago(7d)
| extend Dst = coalesce(DestinationHostName, DestinationIP)
| where Dst has_any (ControllerTerms) or DeviceProduct has_any (ControllerTerms) or AdditionalExtensions has_any (ControllerTerms)
| extend Source = coalesce(SourceHostName, SourceIP)
| where not(SourceIP in (ApprovedSources))
| project TimeGenerated, Vendor=DeviceVendor, Product=DeviceProduct, Source, SourceIP, DestinationIP, Dst, DestinationPort, Protocol, Message, AdditionalExtensions;
let SYS =
Syslog
| where TimeGenerated > ago(7d)
| where Computer has_any (ControllerTerms) or HostIP has_any (ControllerTerms) or SyslogMessage has_any (ControllerTerms) or SyslogMessage has_any (AffectedVersions)
| project TimeGenerated, Computer, HostIP, Facility, SeverityLevel, ProcessName, SyslogMessage;
union FW, SYS
| summarize Events=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated) by tostring(Dst), tostring(Computer), tostring(SourceIP), tostring(DestinationPort)
| order by LastSeen desc;
-- Hunt Windows engineering/BAS-adjacent endpoints for controller-looking artifacts and unexpected network peers.
-- Scope to BMS engineering, jump hosts, and server VLANs; do not run indiscriminately across all fleets.
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)easyio|neo.?series|controller.?backup|config.?export'
OR Exe =~ '(?i)easyio|johnson.?controls|jci|neo'
OR Name =~ '(?i)easyio|jci|bas|bms'
# Verify and harden Windows-based BMS jump hosts/engineering workstations.
# Run read-only first. Set -Apply to create the allowlist inbound firewall rule after change approval.
param(
[switch]$Apply,
[string[]]$ApprovedControllerSubnets = @('10.40.10.0/24','10.40.20.0/24'), # replace with real EasyIO subnets
[string]$RuleName = 'BMS-EasyIO-Management-Allow-Approved-JumpHosts'
)
$ErrorActionPreference = 'SilentlyContinue'
Write-Host '[*] Local admin check and host context'
Get-LocalGroupMember -Group 'Administrators' | Select-Object Name, ObjectClass, PrincipalSource
Write-Host '[*] Listening services and established connections to likely OT/BAS segments'
Get-NetTCPConnection -State Listen, Established |
Where-Object { $_.RemoteAddress -match '^(10\.|172\.(1[6-9]|2[0-9]|3[0-1])\.|192\.168\.)' } |
Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,State,OwningProcess,@{n='Process';e={(Get-Process -Id $_.OwningProcess).ProcessName}} |
Sort-Object RemoteAddress,RemotePort
Write-Host '[*] Searching common data locations for EasyIO/controller export artifacts'
$roots = @($env:USERPROFILE + '\Documents', $env:USERPROFILE + '\Desktop', 'C:\ProgramData', 'D:\Backups')
Get-ChildItem -Path $roots -Recurse -Force -ErrorAction SilentlyContinue |
Where-Object { $_.Name -match '(?i)easyio|neo.?series|controller|bms|bas' -and $_.Extension -match '\.(bak|backup|cfg|config|zip|7z|csv|log)$' } |
Select-Object FullName, Length, CreationTime, LastWriteTime
if ($Apply) {
Write-Host '[*] Creating inbound firewall rule permitting controller management only from approved controller subnets'
New-NetFirewallRule -DisplayName $RuleName -Direction Inbound -Action Allow -Protocol TCP -RemoteAddress $ApprovedControllerSubnets -Profile Domain,Private -Enabled True
}
Write-Host '[*] Review outbound egress. Controllers and jump hosts should not have broad internet access.'
Get-NetFirewallRule -Direction Outbound -Action Allow -Enabled True |
Where-Object { $_.DisplayName -match '(?i)allow|any|internet' } |
Select-Object DisplayName, Enabled, Profile, Action | Format-Table -AutoSize
Remediation
- Confirm exposure immediately. Build or refresh the inventory of EasyIO Neo EC/CW controllers, firmware versions, management interfaces, network paths, remote access, and owning facility. Flag V3.3b63, V3.3b62, V3.3b25, and V3.3b24 as affected pending vendor confirmation.
- Apply the vendor fix. Follow Johnson Controls' CSAF and product security instructions for CVE-2026-64892. Do not rely on the CISA summary alone; download the CSAF/vendor advisory, verify the exact fixed or unaffected release, hash/signature validate firmware where supported, and stage updates through normal OT change control. Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-04
- If a patch cannot be installed this cycle, compensate now. Place affected controllers behind a dedicated OT/BAS DMZ, deny internet egress, block user-VLAN access, and permit management only from named jump hosts/BAS servers over required ports. Remove default/shared accounts, enforce unique credentials, and rotate any credentials, API keys, certificates, SNMP strings, vendor accounts, or saved sessions that could plausibly have been exposed.
- Assume reconnaissance value. Review authentication logs, controller logs, firewall/NDR, remote access gateways, and jump-host process execution for the dwell window. Look for first-time sources touching controllers, unusual config/backup retrieval, firmware queries, credential failures followed by success, and scanning that stops after reaching EC/CW assets.
- Protect engineering paths. Patch and harden Windows engineering workstations and jump hosts; require MFA and conditional access for remote/vendor sessions; use just-in-time access; record sessions; prohibit direct vendor connections into controller VLANs without brokered approval.
- Validate after change. Re-scan passively or with OT-safe methods, confirm versions no longer match the affected list, verify firewall policy with test cases, run backup/restore validation, and obtain facilities sign-off for control continuity. Keep evidence for auditors and cyber insurance.
- Set deadlines. Treat internet-reachable or cross-zone reachable instances as priority within 24-72 hours for isolation even before firmware maintenance. Schedule vendor-guided remediation in the next approved OT window and document risk acceptance only if operations require delay.
Executive Takeaways
- Low CVSS does not equal low operational risk in BAS/OT; sensitive information can be the bridge from IT intrusion to physical process impact.
- Asset inventory and allowlisted access paths are the difference between a manageable exposure and an unbounded hunt.
- Patch according to Johnson Controls CSAF, but do not wait for maintenance windows to isolate reachable controllers and rotate exposed secrets.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.