CISA has published ICS advisory ICSA-26-274-05 disclosing a cleartext transmission vulnerability — tracked as CVE-2026-64893 — in Johnson Controls EasyIO Neo Series EC and CW controllers. These are building automation system (BAS) controllers deployed widely across Critical Manufacturing, Commercial Facilities, and Government Services and Facilities sectors. Successful exploitation allows an attacker positioned on the network to intercept and read sensitive information, including credentials and session data, traversing the controller's management interfaces.
A CVSS v3.1 base score of 5.4 (medium) may tempt teams to deprioritize this one. Don't. In operational technology (OT) environments, cleartext credential exposure is a force multiplier: harvested BAS credentials routinely become the pivot point for lateral movement into broader building management networks, tampering with HVAC and environmental controls, or — in hospital and manufacturing contexts — creating life-safety and production-integrity risk. Every engagement I've run against segmented-but-flat OT networks has turned on exactly this class of weakness.
Technical Analysis
Affected Products and Versions
| Product | Affected Version | CVE |
|---|---|---|
| EasyIO Neo Series EC Controllers | V3.3b62 | CVE-2026-64893 |
| EasyIO Neo Series EC Controllers | V3.3b63 | CVE-2026-64893 |
| EasyIO Neo Series CW Controllers | V3.3b24 | CVE-2026-64893 |
| EasyIO Neo Series CW Controllers | V3.3b25 | CVE-2026-64893 |
CVSS v3.1: 5.4 (Medium) — Vendor: Johnson Controls Weakness: CWE-319 — Cleartext Transmission of Sensitive Information
How the Vulnerability Works
The affected EasyIO Neo firmware versions transmit sensitive data — including authentication credentials and active session tokens — over unencrypted channels. From a defender's perspective, the exploitation chain looks like this:
- Network position: The attacker gains a foothold on the same network segment as the BAS controllers. This can be achieved through a compromised IT asset with dual-homed access, a rogue device on a poorly controlled OT switch port, a compromised contractor laptop, or an upstream pivot from the corporate network where segmentation has failed.
- Passive interception: Using ARP spoofing, a SPAN/mirror port, or simple promiscuous-mode sniffing on a shared segment, the attacker captures traffic between engineering workstations and the EasyIO controllers.
- Credential and session harvesting: Because authentication material and session data are transmitted in cleartext, the attacker reads valid credentials directly off the wire — no brute force, no exploit code, no exploit artifacts on disk.
- Replay and persistence: Harvested session data can be replayed to hijack authenticated sessions, and captured credentials provide durable, legitimate-looking access to the BAS environment.
This is a passive, low-noise attack. It generates no failed logins, no malware, and no anomalous process execution on the controller itself. Detection must therefore focus on network-level indicators: sniffing behavior, unexpected cleartext authentication flows, and unauthorized management-plane access.
Exploitation Status
As of this writing there is no public proof-of-concept, no confirmed in-the-wild exploitation, and CVE-2026-64893 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The advisory originates from coordinated disclosure via CISA. However, exploitation of cleartext transmission flaws requires no specialized exploit — commodity packet-capture tooling is sufficient — so absence of a PoC should not be read as absence of risk.
Detection & Response
Because this vulnerability is exploited passively, your detection strategy must center on two things: (1) identifying where cleartext authentication to these controllers is actually occurring (so you know your exposure), and (2) detecting network interception behavior on OT segments (ARP spoofing, unauthorized sniffing, rogue management access).
Sigma Rules
---
title: Cleartext HTTP Basic Authentication to Building Automation Controller
tid: 2f4c9a71-8d3e-4b6a-9c52-7e1a3f5d8b90
status: experimental
description: Detects HTTP Basic Auth Authorization headers directed at BAS/OT controller addresses, indicating cleartext credential transmission consistent with CVE-2026-64893 exposure on Johnson Controls EasyIO Neo controllers. Populate the ot_controller_ips filter with your EasyIO asset inventory.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05
- https://attack.mitre.org/techniques/T1552/
- https://attack.mitre.org/techniques/T1040/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.credential_access
- attack.t1552
- attack.t1040
logsource:
category: webserver
product: zeek
service: http
detection:
selection:
c-ip|contains:
- '10.90.' # Replace with OT/BAS controller subnets
- '192.168.200.' # Replace with OT/BAS controller subnets
cs-method: 'GET'
cs-uri|contains:
- '/'
Authorization|startswith: 'Basic '
condition: selection
falsepositives:
- Expected engineering workstation traffic prior to remediation - use this rule as an exposure discovery mechanism
level: medium
---
title: Packet Capture or Sniffing Tool Execution on OT-Adjacent Hosts
tid: 8b1e6d42-3a7f-4c9e-b5d1-6f2a8c4e9d73
status: experimental
description: Detects execution of common packet capture tooling on Windows hosts, which may indicate network sniffing used to harvest cleartext BAS credentials per CVE-2026-64893 attack chains. Scope to engineering workstations and OT DMZ jump hosts via your asset tagging.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05
- https://attack.mitre.org/techniques/T1040/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.credential_access
- attack.discovery
- attack.t1040
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\dumpcap.exe'
- '\tshark.exe'
- '\windump.exe'
- '\rawcap.exe'
- '\pktmon.exe'
selection_cli:
CommandLine|contains:
- ' -i '
- ' -w '
- ' capture '
selection_netsh:
Image|endswith: '\netsh.exe'
CommandLine|contains: 'trace start'
condition: (selection_img and selection_cli) or selection_netsh
falsepositives:
- Legitimate network troubleshooting by OT/network engineers - maintain an approved maintenance window list
level: high
---
title: ARP Spoofing or Unexpected Gateway ARP Change on OT Segment
tid: 4d7a2f18-9c6b-4e3d-a8f5-2b9e7c1d6a45
status: experimental
description: Detects gratuitous ARP replies and rapid ARP table churn indicative of ARP spoofing used to intercept cleartext controller traffic (CVE-2026-64893 attack prerequisite). Deploy via Zeek/Suricata ARP logging or switch-level dynamic ARP inspection syslog.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05
- https://attack.mitre.org/techniques/T1557/002/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.credential_access
- attack.collection
- attack.t1557.002
logsource:
category: network
detection:
selection:
event_type:
- 'arp'
- 'dai_violation'
message|contains:
- 'gratuitous'
- 'ARP Inspection'
- 'duplicate address'
condition: selection
falsepositives:
- IP address reassignments during maintenance, failover events on redundant BAS head-ends
level: high
KQL (Microsoft Sentinel / Defender)
The first query hunts for cleartext HTTP sessions to known BAS controller subnets ingested via firewall/Zeek CEF logs. The second hunts for sniffing tool execution on hosts that have network paths to OT segments.
// Hunt 1: Cleartext HTTP (port 80) management traffic to BAS controller subnets
// Populate the subnet list with your EasyIO Neo asset inventory ranges
let OtSubnets = dynamic(["10.90.", "192.168.200."]);
CommonSecurityLog
| where TimeGenerated > ago(7d)
| where DestinationPort == 80
| where DestinationIP startswith "10.90." or DestinationIP startswith "192.168.200."
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
ConnectionCount = count(), SourceHosts = dcount(SourceIP)
by SourceIP, DestinationIP, DestinationPort, DeviceAction
| order by ConnectionCount desc;
// Hunt 2: Packet capture tooling execution on engineering workstations / jump hosts
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where FileName has_any ("dumpcap.exe", "tshark.exe", "windump.exe", "rawcap.exe", "pktmon.exe")
or (FileName =~ "netsh.exe" and ProcessCommandLine has "trace start")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName
| order by TimeGenerated desc;
// Hunt 3: New or unusual source IPs communicating with controller management ports
let KnownEngineers =
DeviceNetworkEvents
| where TimeGenerated > ago(30d) and TimeGenerated < ago(7d)
| where RemotePort in (80, 443, 47808)
| distinct LocalIP;
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where RemotePort in (80, 443, 47808)
| where LocalIP !in (KnownEngineers)
| summarize Connections = count(), Ports = make_set(RemotePort) by LocalIP, RemoteIP, DeviceName
| order by Connections desc;
Velociraptor VQL
For DFIR teams validating whether interception tooling has run on OT-adjacent Windows hosts, hunt for active and historical capture processes plus their capture-file artifacts.
-- Hunt for packet capture tools and capture artifacts on hosts with OT network access
-- Deploy against engineering workstations, BAS front-end servers, and jump hosts
LET capture_procs = SELECT Pid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)(dumpcap|tshark|windump|rawcap|pktmon|wireshark)'
OR CommandLine =~ '(?i)netsh.*trace start'
LET capture_files = SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs=['C:/Users/*/**/*.pcap', 'C:/Users/*/**/*.pcapng',
'C:/Users/*/**/*.cap', 'C:/ProgramData/**/*.pcapng',
'C:/Temp/**/*.pcap', 'C:/Temp/**/*.etl'])
WHERE Mtime > now() - 604800
LET ot_connections = SELECT Pid, Name, Path, Family, Type, Status,
Laddr as LocalAddr, Lport as LocalPort,
Raddr as RemoteAddr, Rport as RemotePort
FROM netstat()
WHERE RemotePort in (80, 443, 47808)
AND Status =~ 'ESTAB'
SELECT * FROM capture_procs
UNION ALL
SELECT NULL, NULL, NULL, NULL, NULL, NULL FROM capture_files LIMIT 0
Run the three sub-queries as separate artifact collection rows or adapt into a multi-source artifact — the key pivots are capture-tool processes, recently written .pcap/.pcapng/.etl files, and live sessions to BAS management ports (80/443) and BACnet/IP (UDP 47808).
Remediation and Verification Script
Use this Bash script on a management host with network access to inventory exposed EasyIO controllers by probing for cleartext HTTP management interfaces, and to verify enforcement after segmentation controls are applied. Pair it with your asset inventory rather than scanning blind across OT ranges.
#!/bin/bash
# CVE-2026-64893 exposure checker - Johnson Controls EasyIO Neo EC/CW controllers
# Run from a secured management host. Never run active scans against OT segments
# without change-control approval and asset owner sign-off.
TARGETS_FILE="easyio_targets.txt" # One controller IP per line, from your CMDB
REPORT="easyio_cleartext_report_$(date +%Y%m%d).csv"
echo "ip,http_open,https_open,basic_auth_cleartext,firmware_banner" > "$REPORT"
while read -r ip; do
[ -z "$ip" ] && continue
http_code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 "http://$ip/" 2>/dev/null)
https_code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 "https://$ip/" 2>/dev/null)
http_open="no"; https_open="no"; cleartext="no"
[ "$http_code" != "000" ] && http_open="yes"
[ "$https_code" != "000" ] && https_open="yes"
# Detect HTTP Basic Auth over cleartext (401 + WWW-Authenticate: Basic on port 80)
auth_hdr=$(curl -sk -I --max-time 5 "http://$ip/" 2>/dev/null | grep -i "WWW-Authenticate: Basic")
[ -n "$auth_hdr" ] && cleartext="YES-EXPOSED"
banner=$(curl -sk -I --max-time 5 "http://$ip/" 2>/dev/null | grep -i "Server:" | tr -d '\r' | tr ',' ';')
echo "$ip,$http_open,$https_open,$cleartext,$banner" | tee -a "$REPORT"
done < "$TARGETS_FILE"
echo ""
echo "=== Hosts with cleartext Basic Auth exposed (CVE-2026-64893 risk) ==="
grep "YES-EXPOSED" "$REPORT" || echo "None found."
echo ""
echo "Next steps: restrict port 80 to controllers via ACL/firewall, verify firmware"
echo "version against ICSA-26-274-05, and confirm HTTPS-only management post-patch."
Remediation
- Inventory immediately. Identify every EasyIO Neo EC controller running V3.3b62/V3.3b63 and every CW controller running V3.3b24/V3.3b25. If you lack a passive OT asset inventory, this is the finding that justifies one — you cannot patch what you cannot enumerate.
- Apply vendor guidance. Review CISA advisory ICSA-26-274-05 (https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05) and the Johnson Controls product security advisory for updated firmware and configuration guidance. Confirm with Johnson Controls technical support which firmware release remediates CVE-2026-64893 before scheduling your maintenance window.
- Enforce encrypted management paths. Where supported, disable HTTP (port 80) management interfaces and enforce HTTPS/TLS only. If the current firmware cannot enforce this, treat network segmentation (below) as the mandatory compensating control until patched.
- Segment the BAS network. Place EasyIO controllers in a dedicated VLAN/zone reachable only from named engineering workstations and the BAS front-end, enforced by firewall ACL or data diode where appropriate. Deny direct controller access from the corporate LAN and block controller-initiated internet egress. This directly defeats the "network position" prerequisite for interception.
- Deploy switch-level anti-spoofing. Enable Dynamic ARP Inspection, DHCP snooping, and port security on OT switches. Disable unused switch ports. These controls specifically counter the ARP-spoofing interception technique this vulnerability invites.
- Rotate credentials after patching. Any credential that has traversed these controllers in cleartext should be considered potentially compromised. Rotate all BAS controller credentials, service accounts, and any reused passwords — especially if engineering credentials are shared with domain or front-end systems.
- Monitor during the exposure window. Deploy the detection content above on your OT DMZ and engineering segments now, before patching completes. Alert on any sniffing tooling, ARP anomalies, or new source IPs touching controller management ports.
Executive Takeaways
- Medium CVSS does not mean low operational risk: cleartext credentials in OT environments are a proven lateral-movement and sabotage vector.
- The attack is passive and artifact-light — you will not detect it on the controller; you must detect it on the network.
- Segmentation and anti-spoofing controls provide immediate risk reduction even before firmware is updated.
- Credential rotation post-remediation is non-negotiable; assume wire-exposed credentials are burned.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.