First published: Thu Dec 02 2021(Updated: )
Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Kantech Entrapass | <8.40 |
Upgrade Entrapass to version 8.40.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-36198 is high with a CVSS score of 7.5.
CVE-2021-36198 allows an unauthorized user to access sensitive data in Johnsoncontrols Kantech Entrapass software.
Version up to exclusive 8.40 of Johnsoncontrols Kantech Entrapass is affected by CVE-2021-36198.
Johnsoncontrols has released a security advisory with mitigation steps for CVE-2021-36198. Please refer to the Johnsoncontrols security advisory for more details.
You can find more information about CVE-2021-36198 on the official US-CERT website and the Johnsoncontrols security advisories page.