First published: Tue Mar 10 2020(Updated: )
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and prior; Kantech EntraPass Global Edition versions 8.0 and prior.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Entrapass | <8.10 | |
Johnsoncontrols Entrapass | <8.10 |
Upgrade impacted Kantech EntraPass Global and Corporate edition software to version 8.10.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7589 is a vulnerability with the SmartService API Service option in Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and pr...
CVE-2019-7589 allows an unauthorized user to potentially upload malicious code to the server that could be executed at system level privileges.
CVE-2019-7589 has a severity level of 9.8, which is considered critical.
To fix CVE-2019-7589, it is recommended to apply the necessary updates or patches provided by Johnson Controls.
You can find more information about CVE-2019-7589 in the security advisories issued by Johnson Controls and the US-CERT advisory ICSA-20-070-04.