CVE-2019-7589: Kantech EntraPass Improper Input Validation
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and prior; Kantech EntraPass Global Edition versions 8.0 and prior.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-7589?
CVE-2019-7589 is a vulnerability with the SmartService API Service option in Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and pr...
How does CVE-2019-7589 affect Johnson Controls' Kantech EntraPass Corporate Edition?
CVE-2019-7589 allows an unauthorized user to potentially upload malicious code to the server that could be executed at system level privileges.
What is the severity level of CVE-2019-7589?
CVE-2019-7589 has a severity level of 9.8, which is considered critical.
How can I fix CVE-2019-7589?
To fix CVE-2019-7589, it is recommended to apply the necessary updates or patches provided by Johnson Controls.
Where can I find more information about CVE-2019-7589?
You can find more information about CVE-2019-7589 in the security advisories issued by Johnson Controls and the US-CERT advisory ICSA-20-070-04.