Описание
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
Ссылки
- Vendor Advisory
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 8.22 (включая)Версия до 8.22 (включая)Версия до 8.22 (включая)
Одно из
cpe:2.3:a:johnsoncontrols:kantech_entrapass:*:*:*:*:corporate:*:*:*
cpe:2.3:a:johnsoncontrols:kantech_entrapass:*:*:*:*:global:*:*:*
cpe:2.3:a:johnsoncontrols:kantech_entrapass:*:*:*:*:special:*:*:*
EPSS
Процентиль: 12%
0.00041
Низкий
8.8 High
CVSS3
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-284
CWE-269
Связанные уязвимости
github
больше 3 лет назад
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
EPSS
Процентиль: 12%
0.00041
Низкий
8.8 High
CVSS3
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-284
CWE-269