Executive Summary
CVE-2026-64893 permits an attacker positioned on the network path to intercept and read sensitive information, including credentials and session data, from Johnson Controls EasyIO Neo Series EC and CW Controllers. The physical risk is downstream: harvested credentials grant control over the building automation logic these devices run, which governs HVAC, pressurization, and environmental setpoints in facilities that may include data centers, hospitals, and critical process spaces.
Technical Exposure Breakdown
The disclosure describes an information exposure condition where sensitive data, specifically authentication credentials and session tokens, is accessible to an attacker who can observe traffic to or from the affected controllers. The failure class points to insufficient or absent transport protection on management or application sessions. When credentials and session identifiers traverse the wire in a form an attacker can read, any adversary with a foothold on the same broadcast domain, a spanned switch port, a compromised engineering workstation, or a man in the middle position can capture them without triggering authentication failures or lockouts.
The following versions are listed as affected in the source data: EasyIO Neo Series EC Controllers V3.3b62 and V3.3b63, and EasyIO Neo Series CW Controllers V3.3b24 and V3.3b25. No CVSS score and no patch status were provided in the grounding data, so operators should treat remediation availability as unconfirmed until Johnson Controls publishes a fix and version mapping.
The attack does not require a flashy exploit. It requires network adjacency and patience. A captured session token can be replayed to assume an authenticated operator context. Captured credentials can be reused against the controller web interface or against other systems if staff reuse passwords, which remains common in OT environments where password managers are rare on field devices.
OT Impact and Compliance Risk
EasyIO Neo controllers are building automation endpoints. Loss of credential confidentiality translates directly to loss of control integrity. An attacker with operator access can alter supply air temperatures, disable economizer logic, force fans off, or manipulate pressurization in spaces where differential pressure is a safety or contamination control. In a data center, environmental manipulation can push server inlet temperatures past thermal thresholds. In a healthcare or laboratory setting, it can defeat containment.
For IEC 62443 programs, this defeats the FR 4 data confidentiality requirement and undermines FR 1 identification and authentication control, because stolen session material bypasses the intended authentication boundary. Facilities under NERC CIP that use these controllers inside an electronic security perimeter must treat cleartext credential exposure as a direct challenge to CIP-005 and CIP-007 access management assumptions. Water and wastewater operators subject to AWIA 2018 risk and resilience obligations should log this as an access control finding affecting building and process support systems.
Compensating Controls
Do not run active scans against these controllers to confirm versions. Building automation field devices are known to fault or reboot under aggressive probing, and a bricked controller can trip the loads it manages. Fingerprint passively from existing network taps and asset inventory instead.
- Segment the controllers onto a dedicated management VLAN and block all lateral access except from a hardened engineering host through a jump server.
- Terminate controller management traffic inside an encrypted transport where the architecture allows, for example an IPsec or TLS tunnel between the engineering host and the segment boundary, so credentials never traverse a shared medium in the clear.
- Rotate all credentials used on the affected controllers and eliminate password reuse across the fleet. Assume any credential used before segmentation is compromised.
- Deploy a Suricata virtual patch concept on the segment uplink: alert on cleartext HTTP authentication headers and session cookies sourced from or destined to controller IP ranges, and alert on session identifier reuse from more than one source address within a short window, which indicates token replay.
- Enable and centralize controller access logs. Watch for authenticated sessions originating from unexpected hosts.
BreachSpider's AI analysis flags cleartext credential exposure as a high value target precisely because it requires no exploit chain, only network position, which is often the easiest thing for an attacker to obtain inside a flat OT network.
BreachSpider Intel
Track CVE-2026-64893 and the broader EasyIO Neo advisory lifecycle through Intel by BreachSpider for version mapping, patch confirmation, and exploitation signals as they develop.