SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-4026

The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607.

MEDIUM 5.0EPSS 1.39%

Does this matter?

Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.

Description

The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.39% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
johnsoncontrols/pegasys p2000 server software · johnsoncontrols/pegasys p2000 server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.