CVE-2012-4026: Johnsoncontrols Pegasys p2000 Server

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607.

Affected products

Published 2012-07-16. Last modified 2026-06-16.