Back

CRITICAL

Kantech EntraPass Improper Input Validation

Published Mar 10, 2020

Description

A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and prior; Kantech EntraPass Global Edition versions 8.0 and prior.

Affected products

Remediation

Vendor solution

Upgrade impacted Kantech EntraPass Global and Corporate edition software to version 8.10.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner jci
Published Mar 10, 2020
Updated Aug 4, 2024
Reserved Feb 7, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner jci
Published Mar 10, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-17127