Johnson Controls Kantech EntraPassÑϳÁ·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-03-11·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-7589£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Kantech EntraPass security management softwareÈçϰ汾£º
Corporate Edition: v8.10֮ǰËùÓа汾
Global Edition: v8.10֮ǰËùÓа汾
·ì϶¸ÅÊö
Johnson Controls Kantech EntraPassÊÇÃÀ¹ú½É×Ô¿Ø£¨JohnsonControls£©¹«Ë¾µÄ°²·ÀÖÎÀíϵͳ¡£
Johnson Controls Kantech EntraPassÖеÄSmartService API·þÎñÑ¡Ïî´æÔÚÒ»¸ö·ì϶£¬Î´¾ÊÚȨµÄÓû§¿ÉÄÜ»áÀûÓô˷ì϶½«¶ñÒâ´úÂëÉÏÔØµ½·þÎñÆ÷£¬¸Ã·þÎñÆ÷Äܹ»ÒÔϵͳ¼¶È¨ÏÞÖ´ÐС£
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£
½¨¸´½¨Òé
Ŀǰ¹Ù·½ÒѰ䲼а汾8.10½¨¸´·ì϶£¬Á´½Ó£ºhttps://www.johnsoncontrols.com/cyber-solutions/security-advisories¡£
»º½â´ëÊ©£º°´Èçϲ½Öè½ûÓÃSmartService API¡£
1. Disable "Use Web Service" within the EntraPass Software.
2. Disable the SmartService from an admin command prompt.
sc config ¡°Kantech.SmartService¡± start=disabled
sc stop ¡°Kantech.SmartService¡±
3. Uninstall the SmartService API from Apps & features.
²Î¿¼Á´½Ó
https://www.us-cert.gov/ics/advisories/icsa-20-070-04


¾©¹«Íø°²±¸11010802024551ºÅ