<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/cna-root/icscert/recent</id>
  <title>Most recent vulnerabilities from the icscert CNA root</title>
  <updated>2026-10-02T07:10:13.608613+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Latest vulnerabilities published by the CNAs operating under the icscert root of the CVE Program.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-27873</id>
    <title>CVE-2026-27873 (jci)</title>
    <updated>2026-10-01T21:27:33.323000+00:00</updated>
    <content>- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.

This issue affects EasyIO FG: before 2.0b52.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-27873"/>
    <summary>- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.

This issue affects EasyIO FG: before 2.0b52.</summary>
    <published>2026-10-01T21:27:33.323000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-64893</id>
    <title>CVE-2026-64893 (jci)</title>
    <updated>2026-10-01T21:25:26.090000+00:00</updated>
    <content>- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.

This issue affects EasyIO NEO: before 3.3b25.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-64893"/>
    <summary>- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.

This issue affects EasyIO NEO: before 3.3b25.</summary>
    <published>2026-10-01T21:25:26.090000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-64892</id>
    <title>CVE-2026-64892 (jci)</title>
    <updated>2026-10-01T21:23:33.947000+00:00</updated>
    <content>- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.

This issue affects Easy IO Neo: before 3.3b63.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-64892"/>
    <summary>- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.

This issue affects Easy IO Neo: before 3.3b63.</summary>
    <published>2026-10-01T21:23:33.947000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-34494</id>
    <title>CVE-2026-34494 (jci)</title>
    <updated>2026-10-01T21:20:55.416000+00:00</updated>
    <content>- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.

This issue affects Neo Series MVP2: before 3.3b63.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-34494"/>
    <summary>- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.

This issue affects Neo Series MVP2: before 3.3b63.</summary>
    <published>2026-10-01T21:20:55.416000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-34493</id>
    <title>CVE-2026-34493 (jci)</title>
    <updated>2026-10-01T21:18:55.348000+00:00</updated>
    <content>- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.

This issue affects EasyIO FS32: before 3.3b63.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-34493"/>
    <summary>- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.

This issue affects EasyIO FS32: before 3.3b63.</summary>
    <published>2026-10-01T21:18:55.348000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-71449</id>
    <title>CVE-2026-71449 (jci)</title>
    <updated>2026-10-01T21:16:57.610000+00:00</updated>
    <content>: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.

This issue affects EasyIO FS32: before 3.0b63.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-71449"/>
    <summary>: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.

This issue affects EasyIO FS32: before 3.0b63.</summary>
    <published>2026-10-01T21:16:57.610000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-71448</id>
    <title>CVE-2026-71448 (jci)</title>
    <updated>2026-10-01T21:15:22.406000+00:00</updated>
    <content>: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.

This issue affects EasyIO FS32: before 3.0b63.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-71448"/>
    <summary>: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.

This issue affects EasyIO FS32: before 3.0b63.</summary>
    <published>2026-10-01T21:15:22.406000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-71454</id>
    <title>CVE-2026-71454 (jci)</title>
    <updated>2026-10-01T21:13:17.159000+00:00</updated>
    <content>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS).

This issue affects CAPEC-63: before 3.0b63.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-71454"/>
    <summary>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS).

This issue affects CAPEC-63: before 3.0b63.</summary>
    <published>2026-10-01T21:13:17.159000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-71453</id>
    <title>CVE-2026-71453 (jci)</title>
    <updated>2026-10-01T21:10:08.583000+00:00</updated>
    <content>- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack.

This issue affects EasyIO FS32: before 3.0b63.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-71453"/>
    <summary>- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack.

This issue affects EasyIO FS32: before 3.0b63.</summary>
    <published>2026-10-01T21:10:08.583000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-71452</id>
    <title>CVE-2026-71452 (jci)</title>
    <updated>2026-10-01T21:06:20.659000+00:00</updated>
    <content>- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection.

This issue affects EasyIO FS32: before 3.0b63.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-71452"/>
    <summary>- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection.

This issue affects EasyIO FS32: before 3.0b63.</summary>
    <published>2026-10-01T21:06:20.659000+00:00</published>
  </entry>
</feed>
