VORANT. Threat Intelligence Research Sign in Create a free account

Johnson Controls EasyIO Neo cleartext credential exposure

routine vulnerability manufacturinggovernment-nationaltransportationenergyinfrastructure

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Johnson Controls EasyIO Neo EC and CW controllers transmit credentials and session data in cleartext over HTTP, allowing interception; fix available, no known exploitation.

CISA published an ICS advisory for Johnson Controls EasyIO Neo Series EC and CW building automation controllers, affecting EC firmware versions V3.3b62 and V3.3b63, and CW firmware versions V3.3b24 and V3.3b25. The vulnerability (CVE-2026-64893, CWE-319) stems from the device transmitting sensitive information, including credentials and session tokens, in cleartext over HTTP, which could allow an attacker on the network path to intercept and read this data and potentially hijack management sessions.

EasyIO Neo is used to manage HVAC, lighting, and energy systems in commercial buildings and is deployed worldwide across critical manufacturing, commercial facilities, government services, transportation, and energy sectors. Johnson Controls has released fixed firmware (EC V3.3b64 and CW V3.3b26) that disables HTTP by default. No public exploitation has been reported, and the vulnerability is noted as having high attack complexity, suggesting it requires network positioning (e.g., man-in-the-middle) to exploit.

Defenders should upgrade affected devices to the fixed firmware versions as soon as operationally feasible. Interim mitigations include enforcing HTTPS/TLS for management access, disabling HTTP, segmenting device networks behind firewalls, using VPNs for remote access, and monitoring for unencrypted HTTP traffic on port 80, cleartext credentials in captures, unexpected access to the web console, ARP spoofing indicators, or unauthorized configuration changes.

Mentioned in this report

Vulnerabilities CVE-2026-64893

Detection guidance

Packet Capture Tool Filtering on HTTP Port 80 (Windows)

ATT&CK T1040

tshark, dumpcap or windump started with a capture filter for cleartext HTTP, matching interception of unencrypted management credentials like those exposed by EasyIO Neo. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Packet Capture Tool Filtering on HTTP Port 80 (Windows)
description: Detects tshark, dumpcap or windump launched with a capture filter on
  HTTP/port 80. Cleartext management interfaces such as the EasyIO Neo web console
  can be sniffed this way to harvest credentials and session tokens. Generalises on
  tool plus HTTP filter, not on a specific host.
tags:
- attack.credential-access
- attack.t1040
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
    - \tshark.exe
    - \dumpcap.exe
    - \windump.exe
  selection_cli:
    CommandLine|contains:
    - port 80
    - tcp.port==80
    - tcp.port == 80
    - http.authorization
    - http.cookie
    - http.request
  condition: selection_img and selection_cli
falsepositives:
- Network engineers troubleshooting web traffic with tshark or Wireshark on a workstation
- Authorized security assessments of building automation or OT networks
level: medium
id: 5ba4dd02-80b3-5972-820f-d2d596fc3a0b
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05

Packet Capture of HTTP Traffic via tcpdump/tshark/ngrep (Linux)

ATT&CK T1040

tcpdump, tshark or ngrep run with a port 80 or HTTP credential filter, consistent with sniffing cleartext credentials on the network path. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Packet Capture of HTTP Traffic via tcpdump/tshark/ngrep (Linux)
description: Detects Linux packet capture utilities started with a port 80 or HTTP
  header and credential filter, consistent with sniffing cleartext credentials and
  session tokens from devices that serve management over HTTP.
tags:
- attack.credential-access
- attack.t1040
logsource:
  category: process_creation
  product: linux
detection:
  selection_img:
    Image|endswith:
    - /tcpdump
    - /tshark
    - /ngrep
  selection_cli:
    CommandLine|contains:
    - port 80
    - tcp port 80
    - http.authorization
    - http.cookie
    - Authorization
    - password
  condition: selection_img and selection_cli
falsepositives:
- Administrators debugging web application traffic on a server
- Network monitoring scripts that capture HTTP samples for troubleshooting
level: medium
id: 06c21c45-e2ac-52fa-9a3a-51eca32f965e
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,566 reports from 152 sources, 502 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs