CVE-2021-27662: KT-1 Capture-replay
Published Sep 15, 2021
·Updated
The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker can record and replay TCP packets. This issue affects Johnson Controls KT-1 all versions up to and including 3.01
Affected Software
2 affected components
Johnsoncontrols Kantech Kt-1 Door Controller Firmware<=3.01
Johnsoncontrols Kantech Kt-1 Door Controller
Remediation
Information
Upgrade the KT-1 controller to version 3.04 and upgrade EntraPass to version 8.40.
Event History
Sep 15, 2021
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-27662.
2
What is the severity of CVE-2021-27662?
The severity of CVE-2021-27662 is high (8.1).
3
What is the affected software?
The affected software is Johnson Controls KT-1 door controller firmware versions up to and including 3.01.
4
What are the possible impacts of this vulnerability?
This vulnerability allows an attacker to perform replay or man-in-the-middle attacks by recording and replaying TCP packets.
5
Are there any solutions or patches available?
Please refer to the Johnson Controls security advisory for information on available solutions or patches.