A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
https://www.us-cert.gov/ics/advisories/ICSA-20-147-02
https://www.johnsoncontrols.com/cyber-solutions/security-advisories