First published: Tue May 26 2020(Updated: )
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Kantech Entrapass | <=8.22 | |
Johnsoncontrols Kantech Entrapass | <=8.22 | |
Johnsoncontrols Kantech Entrapass | <=8.22 |
Upgrade all Kantech EntraPass Editions to version 8.23. Registered users can obtain the critical software update by downloading the zip file from the Software Downloads location at https://kantech.com/Support/SoftwareDownloads.aspx.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9046 is a vulnerability in all versions of Kantech EntraPass Editions that could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
All versions of Kantech EntraPass Editions up to and including version 8.22 are affected by CVE-2020-9046.
CVE-2020-9046 has a severity rating of 7.8 (High).
An authorized low-privileged user can exploit CVE-2020-9046 by replacing critical files with specially crafted files.
You can find more information about CVE-2020-9046 in the security advisories published by Johnson Controls and the US-CERT website.