CVE-2020-9046: Kantech EntraPass Security Management Software - System Permissions Vulnerability
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-9046?
CVE-2020-9046 is a vulnerability in all versions of Kantech EntraPass Editions that could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
What software versions are affected by CVE-2020-9046?
All versions of Kantech EntraPass Editions up to and including version 8.22 are affected by CVE-2020-9046.
What is the severity of CVE-2020-9046?
CVE-2020-9046 has a severity rating of 7.8 (High).
How can an authorized low-privileged user exploit CVE-2020-9046?
An authorized low-privileged user can exploit CVE-2020-9046 by replacing critical files with specially crafted files.
Where can I find more information about CVE-2020-9046?
You can find more information about CVE-2020-9046 in the security advisories published by Johnson Controls and the US-CERT website.