Back to all lessons
Awareness Lessons
last week

Johnson Controls EasyIO Neo Controllers Expose Sensitive Data via Unpatched Firmware

A vulnerability in Johnson Controls EasyIO Neo Series EC and CW Controllers allows attackers to access sensitive information that could be leveraged for further, more damaging attacks against operational technology environments. The affected firmware versions were widely deployed before the flaw was identified, highlighting the risks of delayed patch cycles in industrial control systems. Because these controllers are often embedded in building management and critical infrastructure systems, the exposure window can be prolonged if firmware updates are not treated with urgency. This incident underscores that OT/ICS environments are just as susceptible to information-disclosure vulnerabilities as traditional IT systems, and that firmware lifecycle management must be a priority.

Tactical Insight

Immediate actions

  • Upgrade all affected EC Controllers to V3.3b64 and CW Controllers to V3.3b26 as released by Johnson Controls without delay.
  • Audit your environment to identify every deployed EasyIO Neo Series device and confirm which firmware version each is running.
  • Restrict network access to affected controllers through firewall rules or ACLs until patching is confirmed complete.

Long-term improvements

  • Maintain a continuously updated inventory of all OT/ICS devices, including firmware versions, using an asset management platform.
  • Establish a formal OT patch management policy that defines maximum allowable patch windows for critical infrastructure firmware.
  • Implement network segmentation to isolate building management and industrial control systems from corporate IT networks and the internet.

Detection measures

  • Deploy continuous vulnerability scanning tools capable of identifying unpatched firmware versions across OT environments.
  • Configure logging and alerting on controllers and network perimeters to detect anomalous access attempts targeting sensitive data endpoints.
  • Subscribe to vendor security advisories and ICS-CERT notifications to receive timely alerts about newly disclosed vulnerabilities.