← All Advisories

CVE-2026-64893

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-64893

Key Details

CVECVE-2026-64893
CVSS Score / Version7.3 (High) / CVSS v4.0
Updated2026-10-02
Affected productsJohnson Controls EasyIO NEO
Classified asCWE-319 (Cleartext Transmission of Sensitive Information)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Johnson ControlsEasyIO NEO
SubsystemsGeneral OT
SectorsMultiple

What to Know

- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.

This issue affects EasyIO NEO: before 3.3b25. (NVD)

What to Do

Monitor Johnson Controls's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-64893
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-64893