Johnson Controls Kantech EntraPassÑϳÁ·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-7589£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Kantech EntraPass security management softwareÈçϰ汾£º

Corporate Edition: v8.10֮ǰËùÓа汾

Global Edition: v8.10֮ǰËùÓа汾


·ì϶¸ÅÊö


Johnson Controls Kantech EntraPassÊÇÃÀ¹ú½­É­×Ô¿Ø£¨JohnsonControls£©¹«Ë¾µÄ°²·ÀÖÎÀíϵͳ ¡£

Johnson Controls Kantech EntraPassÖеÄSmartService API·þÎñÑ¡Ïî´æÔÚÒ»¸ö·ì϶£¬Î´¾­ÊÚȨµÄÓû§¿ÉÄÜ»áÀûÓô˷ì϶½«¶ñÒâ´úÂëÉÏÔØµ½·þÎñÆ÷£¬¸Ã·þÎñÆ÷Äܹ»ÒÔϵͳ¼¶È¨ÏÞÖ´ÐÐ ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP ¡£


½¨¸´½¨Òé


Ŀǰ¹Ù·½ÒѰ䲼а汾8.10½¨¸´·ì϶£¬Á´½Ó£ºhttps://www.johnsoncontrols.com/cyber-solutions/security-advisories ¡£

»º½â´ëÊ©£º°´Èçϲ½Öè½ûÓÃSmartService API ¡£


1. Disable "Use Web Service" within the EntraPass Software.


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2. Disable the SmartService from an admin command prompt.

sc config ¡°Kantech.SmartService¡± start=disabled

sc stop ¡°Kantech.SmartService¡±


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


3. Uninstall the SmartService API from Apps & features.


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-070-04