Johnson Controls Kantech EntraPassÑÏÖØÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-7589£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Kantech EntraPass security management softwareÈçϰ汾£º

Corporate Edition: v8.10֮ǰËùÓа汾

Global Edition: v8.10֮ǰËùÓа汾


Îó²î¸ÅÊö


Johnson Controls Kantech EntraPassÊÇÃÀ¹ú½­É­×Ô¿Ø£¨JohnsonControls£©¹«Ë¾µÄ°²·ÀÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£¡£

Johnson Controls Kantech EntraPassÖеÄSmartService APIЧÀÍÑ¡Ïî±£´æÒ»¸öÎó²î£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄÓû§¿ÉÄÜ»áʹÓôËÎó²î½«¶ñÒâ´úÂëÉÏÔØµ½Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬¸ÃЧÀÍÆ÷¿ÉÒÔÒÔϵͳ¼¶È¨ÏÞÖ´ÐС£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½ÒÑÐû²¼Ð°汾8.10ÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬Á´½Ó£ºhttps://www.johnsoncontrols.com/cyber-solutions/security-advisories¡£¡£¡£¡£¡£¡£¡£

»º½â²½·¥£º°´Èçϰ취½ûÓÃSmartService API¡£¡£¡£¡£¡£¡£¡£


1. Disable "Use Web Service" within the EntraPass Software.


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


2. Disable the SmartService from an admin command prompt.

sc config ¡°Kantech.SmartService¡± start=disabled

sc stop ¡°Kantech.SmartService¡±


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


3. Uninstall the SmartService API from Apps & features.


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-070-04