PatchSiren cyber security CVE debrief
CVE-2024-2420 LenelS2 CVE debrief
CVE-2024-2420 is a critical authentication bypass vulnerability in LenelS2 NetBox, an access control and event monitoring system used in physical security environments. The vulnerability stems from hard-coded credentials present in versions prior to and including 5.6.1, enabling unauthenticated attackers to gain unauthorized access to affected systems. Published by CISA on May 30, 2024, this vulnerability carries a CVSS 3.1 score of 9.8 (Critical), reflecting its network-exploitable nature, low attack complexity, and high impact on confidentiality, integrity, and availability. The affected product is LenelS2 NetBox versions below 5.6.2. Carrier has released NetBox version 5.6.2 to address this issue. Organizations should prioritize upgrading to the patched version and consult the NetBox hardening guide for secure deployment practices.
- Vendor
- LenelS2
- Product
- NetBox
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-05-30
- Original CVE updated
- 2024-05-30
- Advisory published
- 2024-05-30
- Advisory updated
- 2024-05-30
Who should care
Organizations using LenelS2 NetBox for physical access control and security event monitoring, particularly in critical infrastructure, commercial facilities, and enterprise environments. Security teams responsible for ICS/OT security, facility managers, and physical security administrators should prioritize this patch.
Technical summary
LenelS2 NetBox versions prior to 5.6.2 contain hard-coded credentials that allow attackers to bypass authentication requirements entirely. The vulnerability is remotely exploitable over the network without any user interaction or privileges. Successful exploitation grants attackers full administrative access to the access control and event monitoring system, compromising physical security operations. The CVSS 3.1 score of 9.8 reflects critical impact across confidentiality, integrity, and availability dimensions. Carrier released NetBox 5.6.2 as the definitive fix.
Defensive priority
critical
Recommended defensive actions
- Upgrade LenelS2 NetBox to version 5.6.2 by contacting your authorized installer.
- Follow the NetBox hardening guide available in the built-in help menu for secure deployment.
- Review and apply CISA's ICS recommended practices for industrial control system security.
- Monitor for unauthorized access attempts in NetBox audit logs.
- Restrict network access to NetBox management interfaces to authorized administrative hosts only.
Evidence notes
CISA published advisory ICSA-24-151-01 on May 30, 2024, confirming hard-coded credentials in NetBox versions ≤5.6.1. The advisory specifies that version 5.6.2 mitigates the vulnerability. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H confirms network-based exploitation without authentication.
Official resources
-
CVE-2024-2420 CVE record
CVE.org
-
CVE-2024-2420 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-05-30