Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kantech EntraPass Improper Input Validation
Vulnerability Description
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and prior; Kantech EntraPass Global Edition versions 8.0 and prior.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
Johnson Controls Kantech EntraPass 输入验证错误漏洞
Vulnerability Description
Johnson Controls Kantech EntraPass是美国江森自控(Johnson Controls)公司的一款菜单驱动式的安防管理系统。 Johnson Controls Kantech EntraPass Corporate Edition 8.0及之前版本和Kantech EntraPass Global Edition 8.0及之前版本中的SmartService API Service选项存在输入验证错误漏洞。攻击者可利用该漏洞以系统权限执行恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A