← Back

Entrapass

entrapass

Vendor: Johnsoncontrols • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Johnsoncontrols
1Entrapass
Jun 17, 2026
Mar 10, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This a...Show more
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and prior; Kantech EntraPass Global Edition versions 8.0 and prior.Show less