What CISOs need to know: Johnson Controls EasyIO FG
A dod_stig signal from CISA Cybersecurity Advisories - and what compliance teams should do this week.
Published 2026-10-07
# What CISOs need to know: Johnson Controls EasyIO FG
What happened
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-279-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device.</strong></p> <p>The following versions of Johnson Controls EasyIO FG are affected:</p> <ul> <li>EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873)</li> </ul> <div class="csaf-table"> <table class="tablesaw tablesaw-stack"> <thead> <tr> <th>CVSS</th> <th>Vendor</th> <th>Equipment</th> </tr> </thead> <tbody> <tr> <td>v3 7.7</td> <td>Johnson Controls</td> <td>EasyIO FG firmware</td> </tr> </tbody> </table> <table class="tablesaw tablesaw-stack"> <thead> <tr> <th>2 Vulnerabilities</th> </tr> </thead> <tbody> <tr> <td>Use of Hard-coded Credentials, Improper Privilege Management</td> </tr> </tbody> </table> </div> <h3>Background</h3> <ul> <li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li> <li><strong>Countries/Areas Deployed: </strong>Worldwide</li> <li><strong>Company Headquarters Location: </strong>Ireland</li> </ul> <hr /> <h2>Vulnerabilities</h2> <div class="icsa-etb-toggle-wrapper"><a class="icsa-etb-toggle-all" href="https://www.cisa.gov/">Expand All +</a></div> <div class="c-expandable-textbox icsa-etb"> <div class="c-expandable-textbox__title">CVE-2026-27872</div> <div class="c-expandable-textbox__body">A vulnerability exists in EasyIO FG relating to an attacker gaining unauthorized access to the system through hard-coded credentials and improper privilege management, potentially resulting in full device compromise. Successful exploitation could result in technical or operational impact.</div> <div class="c-expandable-textbox-morebutton-wrapper"><a class="c-expandable-textbox-morebutton" href="https://www.cisa.gov/">Read More</a></div> <div class="c-expandable-textbox__body2"> <h4>1 Affected Product</h4> <hr /> <h5>Johnson Controls EasyIO FG firmware: <=2.0b52</h5> <div> <p>Product Status: known_affected</p> </div> <h6>Remediations</h6> <div> <p><strong>Mitigation</strong><br />Johnson Controls has determined that the EasyIO FG Series has reached End-of-Life (EOL) and End-of-Support (EOS) status. The product has not been manufactured or sold since prior to 2019, and the source code is no longer available. As a result, no firmware patch or code-level fix will be issued. Users are advised to migrate to supported current-generation products (e.g., EasyIO Neo R1 Series).</p> </div> <div> <p><strong>Mitigation</strong><br />Deploy devices only within isolated BAS/OT networks</p> </div> <div> <p><strong>Mitigation</strong><br />Ensure no direct Internet exposure</p> </div> <div> <p><strong>Mitigation</strong><br />Enforce strict VLAN segmentation from enterprise IT networks</p> </div> <div> <p><strong>Mitigation</strong><br />Restrict access to trusted engineering workstations only</p> </div> <div> <p><strong>Mitigation</strong><br />Block all remote login access from untrusted networks</p> </div> <div> <p><strong>Mitigation</strong><br />Allow connections only from whitelisted IP addresses</p> </div> <div> <p><strong>Mitigation</strong><br />Block all Internet-originated traffic</p> </div> <div> <p><strong>Mitigation</strong><br />Prevent unauthorized lateral movement across networks</p> </div> <div> <p><strong>Mitigation</strong><br />Restrict communication to required protocols only</p> </div> <div> <p><strong>Mitigation</strong><br />Disable insecure services (e.g., Telnet), if enabled</p> </div> <div> <p><strong>Mitigation</strong><br />Disable any unnecessary services or exposed ports</p> </div> <div> <p><strong>Mitigation</strong><br />Monitor for repeated login attempts</p> </div> <div> <p><strong>Mitigation</strong><br />Monitor for unauthorized or root-level access</p> </div> <div> <p><strong>Mitigation</strong><br />Enable logging and centralized monitoring (where supported)</p> </div> <div> <p><strong>Mitigation</strong><br />Restrict distribution of firmware images</p> </div> <div> <p><strong>Mitigation</strong><br />Prevent unauthorized physical and console access</p> </div> <div> <p><strong>Mitigation</strong><br />For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-12 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</p> </div> <hr /> <h6>Additional Metrics</h6> <p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/798.html">CWE-798 Use of Hard-coded Credentials</a></p> <div class="csaf-table csaf-metrics-table"> <table class="tablesaw tablesaw-stack"> <thead> <tr> <th>CVSS Version</th> <th>Base Score</th> <th>Base Severity</th> <th>Vector String</th> </tr> </thead> <tbody> <tr> <td>3.1</td> <td>7.7</td> <td>HIGH</td> <td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H</a></td> </tr> <tr> <td>4.0</td> <td>7.2</td> <td>HIGH</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H">CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H</a></td> </tr> </tbody> </table> </div> <hr /> <p><a href="https://www.cve.org/CVERecord?id=CVE-2026-27872">View CVE Details</a></p> </div> </div> <div class="c-expandable-textbox icsa-etb"> <div class="c-expandable-textbox__title">CVE-2026-27873</div> <div class="c-expandable-textbox__body">A vulnerability exists in EasyIO FG relating to an attacker gaining unauthorized access to the system through hard-coded credentials and improper privilege management, potentially resulting in full device compromise. Successful exploitation could result in technical or operational impact.</div> <div class="c-expandable-textbox-morebutton-wrapper"><a class="c-expandable-textbox-morebutton" href="https://www.cisa.gov/">Read More</a></div> <div class="c-expandable-textbox__body2"> <h4>2 Affected Products</h4> <hr /> <h5>Johnson Controls EasyIO FG firmware: <=2.0b52</h5> <div> <p>Product Status: known_affected</p> </div> <h6>Remediations</h6> <div> <p><strong>Mitigation</strong><br />Johnson Controls has determined that the EasyIO FG Series has reached End-of-Life (EOL) and End-of-Support (EOS) status. The product has not been manufactured or sold since prior to 2019, and the source code is no longer available. As a result, no firmware patch or code-level fix will be issued. Users are advised to migrate to supported current-generation products (e.g., EasyIO Neo R1 Series).</p> </div> <div> <p><strong>Mitigation</strong><br />Deploy devices only within isolated BAS/OT networks</p> </div> <div> <p><strong>Mitigation</strong><br />Ensure no direct Internet exposure</p> </div> <div> <p><strong>Mitigation</strong><br />Enforce strict VLAN segmentation from enterprise IT networks</p> </div> <div> <p><strong>Mitigation</strong><br />Restrict access to trusted engineering workstations only</p> </div> <div> <p><strong>Mitigation</strong><br />Block all remote login access from untrusted networks</p> </div> <div> <p><strong>Mitigation</strong><br />Allow connections only from whitelisted IP addresses</p> </div> <div> <p><strong>Mitigation</strong><br />Block all Internet-originated traffic</p> </div> <div> <p><strong>Mitigation</strong><br />Prevent unauthorized lateral movement across networks</p> </div> <div> <p><strong>Mitigation</strong><br />Restrict communication to required protocols only</p> </div> <div> <p><strong>Mitigation</strong><br />Disable insecure services (e.g., Telnet), if enabled</p> </div> <div> <p><strong>Mitigation</strong><br />Disable any unnecessary services or exposed ports</p> </div> <div> <p><strong>Mitigation</strong><br />Monitor for repeated login attempts</p> </div> <div> <p>
Source: CISA Cybersecurity Advisories
Why it matters
This signal sits squarely in the DoD STIG Readiness + ACAS / SCAP audit alignment territory. CISOs and compliance leads at mid-market EU/US organisations should map it to their control set within the next 7-14 days.
What to do this week
1. Read the source advisory in full and identify whether your environment is in scope. 2. Check existing controls against the requirement / vulnerability. 3. Document evidence of remediation or non-applicability - auditors will ask.
How RDS GoSOC AI helps
RDS GoSOC AI is a multi-tenant AI SOC + compliance platform that maps 16 frameworks (NIS2, DoD STIG, EU AI Act, SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, and more) into one dashboard. Start the 14-day free trial - every paid feature unlocked, no credit card. The in-app User Guide tab walks through every feature and Sage handles setup questions in-context.
---
#MSP #ManagedServices #CMMC #FedRamp #CyberSecurity #SOC #SecurityOperations #MSSP #ThreatDetection #Compliance #CloudSecurity #IdentitySecurity #SecurityMonitoring #ITServices #CyberResilience #ManagedSecurity #BusinessGrowth