The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

Johnson Controls disclosed CVE-2026-64893, a medium-severity vulnerability affecting EasyIO Neo Series EC and CW Controllers used in building automation systems worldwide. The vulnerability allows attackers to intercept sensitive information including credentials and session data transmitted in cleartext over HTTP connections. Affected versions include EC Controllers V3.3b62 and V3.3b63, and CW Controllers V3.3b24 and V3.3b25, with fixes available in V3.3b64 and V3.3b26 respectively.

This incident highlights the persistent security challenges in operational technology environments where legacy protocols and unencrypted communications remain prevalent. As building automation systems become increasingly connected and targeted by threat actors, the exposure of credentials through cleartext transmission represents a critical attack vector for lateral movement within enterprise networks.

Why This Matters Now

Building automation systems are increasingly targeted as entry points for ransomware and espionage campaigns, making the secure transmission of credentials and session data critical for preventing broader network compromise in critical infrastructure environments.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerability allows attackers to intercept credentials and session data transmitted in cleartext, potentially leading to unauthorized access to building automation systems.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would be highly relevant to this building automation attack as it could segment network access and reduce the blast radius of credential compromise across IoT and operational technology systems.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native security controls would likely reduce the scope of credential interception by constraining network visibility and limiting attacker positioning for man-in-the-middle attacks across building automation segments

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely constrain the scope of compromised credentials by limiting administrative access to specific controller segments rather than broad building automation network privileges

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely reduce lateral movement capabilities by constraining inter-controller communications and limiting pivoting between different building automation system segments

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Visibility and control mechanisms would likely detect and constrain anomalous command patterns, reducing attacker ability to maintain persistent administrative sessions across multiple building automation controllers

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely constrain data exfiltration by limiting outbound communications from building automation networks and reducing the volume of operational data that could be transmitted externally

Impact (Mitigations)

Remaining impact would likely be contained to specific building automation zones rather than facility-wide disruption, with reduced ability to affect critical infrastructure operations across multiple systems simultaneously

Impact at a Glance

Affected Business Functions

  • HVAC Control Systems
  • Building Automation
  • Energy Management Systems
  • Lighting Control
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: N/A

Data Exposure

Network credentials, session tokens, and building automation system authentication data transmitted in cleartext, potentially exposing facility management access and operational control credentials.

Recommended Actions

  • • Implement Encrypted Traffic (HPE) capabilities to prevent cleartext transmission of sensitive credentials and session data in building automation networks
  • • Deploy Zero Trust Segmentation to isolate building automation controllers and limit lateral movement between network segments
  • • Enable Multicloud Visibility & Control to monitor and detect unencrypted HTTP traffic and unauthorized access to management interfaces
  • • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration from building automation systems
  • • Deploy Threat Detection & Anomaly Response capabilities to identify man-in-the-middle attacks and credential interception attempts on industrial control networks

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image