CVE-2026-64893: High severity Johnson Controls EasyIO NEO vulnerability
Published Oct 1, 2026
·Updated
- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.
This issue affects EasyIO NEO: before 3.3b25.
Affected Software
1 affected component
Johnson Controls EasyIO NEO<3.3b25
Event History
Oct 1, 2026
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
DescriptionWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which EasyIO NEO versions are affected?
EasyIO NEO versions before 3.3b25 are affected.
2
What access does an attacker need to exploit this issue?
An attacker must be able to conduct a man-in-the-middle attack on communications involving the affected EasyIO NEO system.