CVE-2019-7589

CRITICAL

A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system l...

Affects 1 product across 1 vendor.

BCS6.89
CVSS 3.19.8
EPSS1.6%
Percentile75th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-20: Improper Input Validation

Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.

Related Attack Patterns (CAPEC)
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
via CWE-20
CAPEC-7 Blind SQL Injection
via CWE-20
CAPEC-8 Buffer Overflow in an API Call
via CWE-20
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-20
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-20
Show all 51
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability in the SmartService API Service option of Johnson Controls' Kantech EntraPass Corporate Edition and Global Edition versions 8.0 and prior allows unauthorized users to upload and execute malicious code with system-level privileges.

BSID: BS-2020-GLOBAL-141219-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2019-7589?
A critical vulnerability in the SmartService API Service option of Johnson Controls' Kantech EntraPass Corporate Edition and Global Edition versions 8.0 and prior allows unauthorized users to upload and execute malicious code with system-level privileges.
What is the CVSS score for CVE-2019-7589?
CVE-2019-7589 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.6%.
Is CVE-2019-7589 actively exploited?
No confirmed active exploitation of CVE-2019-7589 as of 2026-09-25.
How do I remediate CVE-2019-7589?
Priority: IMMEDIATE.
What systems are affected by CVE-2019-7589?
CVE-2019-7589 affects: Johnsoncontrols.
Vulnerability Details
CVE IDCVE-2019-7589
BSIDBS-2020-GLOBAL-141219-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2020-03-10
Last Modified2026-06-17
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and prior; Kantech EntraPass Global Edition versions 8.0 and prior.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack vector involves an unauthorized user exploiting the SmartService API Service option to upload malicious code to the server. This code can then be executed with system-level privileges, potentially leading to full system compromise.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductAffected Versions
Johnsoncontrols Entrapass < 8.10
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 2395 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashb83387f13b8b2710fcb44eceaf15c6548e4371fa131b69c9bb931dace523d741ef1babbcd9740d3f24e3aaf346aff0fb6a987a53e1985a3a352804033afb2926
Related CVEs affecting Johnsoncontrols
CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2014-5428 10.0 Unrestricted file upload vulnerability in unspecified web services in Johnson... CVE-2021-36205 9.8 Under certain circumstances the session token is not cleared on logout. CVE-2021-27663 9.8 A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems... CVE-2021-27664 9.8 Under certain configurations an unauthenticated remote user could be given ac...
View all Johnsoncontrols CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →