VYPR
Unrated severityNVD Advisory· Published Jul 16, 2012· Updated Apr 29, 2026

CVE-2012-2607

CVE-2012-2607

Description

The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port).

Affected products

3
  • cpe:2.3:h:johnsoncontrols:network_controller:ck721-a:*:*:*:*:*:*:*
  • cpe:2.3:o:johnsoncontrols:network_controller_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:johnsoncontrols:network_controller_firmware:*:*:*:*:*:*:*:*range: <=03.1.0.14
    • cpe:2.3:o:johnsoncontrols:network_controller_firmware:03.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.