CVE-2019-7589
Kantech EntraPass Improper Input Validation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and prior; Kantech EntraPass Global Edition versions 8.0 and prior.
Hay una vulnerabilidad con la opción SmartService API Service por la cual un usuario no autorizado podría explotar esto para cargar código malicioso en el servidor que podría ser ejecutado con privilegios nivel system. Esto afecta a Kantech EntraPass Corporate Edition versiones 8.0 y anteriores; Kantech EntraPass Global Edition versiones 8.0 y anteriores de Johnson Controls.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-07 CVE Reserved
- 2020-03-10 CVE Published
- 2024-08-04 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.us-cert.gov/ics/advisories/icsa-20-070-04 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | 2020-03-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Johnsoncontrols Search vendor "Johnsoncontrols" | Entrapass Search vendor "Johnsoncontrols" for product "Entrapass" | < 8.10 Search vendor "Johnsoncontrols" for product "Entrapass" and version " < 8.10" | corporate |
Affected
| ||||||
Johnsoncontrols Search vendor "Johnsoncontrols" | Entrapass Search vendor "Johnsoncontrols" for product "Entrapass" | < 8.10 Search vendor "Johnsoncontrols" for product "Entrapass" and version " < 8.10" | global |
Affected
|