SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-7589

A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges.

CRITICAL 9.8EPSS 1.60%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and prior; Kantech EntraPass Global Edition versions 8.0 and prior.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.60% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
johnsoncontrols/entrapass
Source
productsecurity@jci.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.