Vulnerability Description
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Johnsoncontrols | Kantech Entrapass | <= 8.22 |
Related Weaknesses (CWE)
References
- https://www.johnsoncontrols.com/cyber-solutions/security-advisoriesVendor Advisory
- https://www.us-cert.gov/ics/advisories/ICSA-20-147-02Third Party AdvisoryUS Government Resource
- https://www.johnsoncontrols.com/cyber-solutions/security-advisoriesVendor Advisory
- https://www.us-cert.gov/ics/advisories/ICSA-20-147-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-9046?
CVE-2020-9046 is a vulnerability with a CVSS score of 8.8 (HIGH). A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifical...
How severe is CVE-2020-9046?
CVE-2020-9046 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9046?
Check the references section above for vendor advisories and patch information. Affected products include: Johnsoncontrols Kantech Entrapass.