CVE-2019-7589
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and prior; Kantech EntraPass Global Edition versions 8.0 and prior.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- johnsoncontrols/entrapass
- Source
- productsecurity@jci.com
References
- https://www.johnsoncontrols.com/cyber-solutions/security-advisoriesVendor Advisory
- https://www.us-cert.gov/ics/advisories/icsa-20-070-04Third Party Advisory, US Government Resource
- https://www.johnsoncontrols.com/cyber-solutions/security-advisoriesVendor Advisory
- https://www.us-cert.gov/ics/advisories/icsa-20-070-04Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.