Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast its MAC address, serial number, and firmware version. Once configured, the controller will no longer broadcast this information.
CVE ID: CVE-2024-32754
CVSS Base Severity: LOW
CVSS Base Score: 3.1
CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vendor: Johnson Controls
Product: Kantech KT1 Door Controller, Rev01, Kantech KT2 Door Controller, Rev01, Kantech KT400 Door Controller, Rev01
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 10.71% (scored less or equal to compared to others)
EPSS Date: 2025-05-30 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: egress
SSVC Automatable: false