Johnson Controls Kantech EntraPassÑϳÁ·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-7589 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Kantech EntraPass security management softwareÈçϰ汾£º

Corporate Edition: v8.10֮ǰËùÓа汾

Global Edition: v8.10֮ǰËùÓа汾


·ì϶¸ÅÊö


Johnson Controls Kantech EntraPassÊÇÃÀ¹ú½­É­×Ô¿Ø£¨JohnsonControls£©¹«Ë¾µÄ°²·ÀÖÎÀíϵͳ¡£

Johnson Controls Kantech EntraPassÖеÄSmartService API·þÎñÑ¡Ïî´æÔÚÒ»¸ö·ì϶ £¬Î´¾­ÊÚȨµÄÓû§¿ÉÄÜ»áÀûÓô˷ì϶½«¶ñÒâ´úÂëÉÏÔØµ½·þÎñÆ÷ £¬¸Ã·þÎñÆ÷Äܹ»ÒÔϵͳ¼¶È¨ÏÞÖ´ÐС£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£


½¨¸´½¨Òé


Ŀǰ¹Ù·½ÒѰ䲼а汾8.10½¨¸´·ì϶ £¬Á´½Ó£ºhttps://www.johnsoncontrols.com/cyber-solutions/security-advisories¡£

»º½â´ëÊ©£º°´Èçϲ½Öè½ûÓÃSmartService API¡£


1. Disable "Use Web Service" within the EntraPass Software.


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2. Disable the SmartService from an admin command prompt.

sc config ¡°Kantech.SmartService¡± start=disabled

sc stop ¡°Kantech.SmartService¡±


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3. Uninstall the SmartService API from Apps & features.


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-070-04