CVE-2020-9046

A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:johnsoncontrols:kantech_entrapass:*:*:*:*:corporate:*:*:*
cpe:2.3:a:johnsoncontrols:kantech_entrapass:*:*:*:*:global:*:*:*
cpe:2.3:a:johnsoncontrols:kantech_entrapass:*:*:*:*:special:*:*:*

History

21 Nov 2024, 05:39

Type Values Removed Values Added
CVSS v2 : 7.2
v3 : 7.8
v2 : 7.2
v3 : 8.8
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory
References () https://www.us-cert.gov/ics/advisories/ICSA-20-147-02 - Third Party Advisory, US Government Resource () https://www.us-cert.gov/ics/advisories/ICSA-20-147-02 - Third Party Advisory, US Government Resource

Information

Published : 2020-05-26 21:15

Updated : 2024-11-21 05:39


NVD link : CVE-2020-9046

Mitre link : CVE-2020-9046

CVE.ORG link : CVE-2020-9046


JSON object : View

Products Affected

johnsoncontrols

  • kantech_entrapass
CWE
CWE-284

Improper Access Control

CWE-269

Improper Privilege Management