PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-2420 LenelS2 CVE debrief

CVE-2024-2420 is a critical authentication bypass vulnerability in LenelS2 NetBox, an access control and event monitoring system used in physical security environments. The vulnerability stems from hard-coded credentials present in versions prior to and including 5.6.1, enabling unauthenticated attackers to gain unauthorized access to affected systems. Published by CISA on May 30, 2024, this vulnerability carries a CVSS 3.1 score of 9.8 (Critical), reflecting its network-exploitable nature, low attack complexity, and high impact on confidentiality, integrity, and availability. The affected product is LenelS2 NetBox versions below 5.6.2. Carrier has released NetBox version 5.6.2 to address this issue. Organizations should prioritize upgrading to the patched version and consult the NetBox hardening guide for secure deployment practices.

Vendor
LenelS2
Product
NetBox
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-05-30
Original CVE updated
2024-05-30
Advisory published
2024-05-30
Advisory updated
2024-05-30

Who should care

Organizations using LenelS2 NetBox for physical access control and security event monitoring, particularly in critical infrastructure, commercial facilities, and enterprise environments. Security teams responsible for ICS/OT security, facility managers, and physical security administrators should prioritize this patch.

Technical summary

LenelS2 NetBox versions prior to 5.6.2 contain hard-coded credentials that allow attackers to bypass authentication requirements entirely. The vulnerability is remotely exploitable over the network without any user interaction or privileges. Successful exploitation grants attackers full administrative access to the access control and event monitoring system, compromising physical security operations. The CVSS 3.1 score of 9.8 reflects critical impact across confidentiality, integrity, and availability dimensions. Carrier released NetBox 5.6.2 as the definitive fix.

Defensive priority

critical

Recommended defensive actions

  • Upgrade LenelS2 NetBox to version 5.6.2 by contacting your authorized installer.
  • Follow the NetBox hardening guide available in the built-in help menu for secure deployment.
  • Review and apply CISA's ICS recommended practices for industrial control system security.
  • Monitor for unauthorized access attempts in NetBox audit logs.
  • Restrict network access to NetBox management interfaces to authorized administrative hosts only.

Evidence notes

CISA published advisory ICSA-24-151-01 on May 30, 2024, confirming hard-coded credentials in NetBox versions ≤5.6.1. The advisory specifies that version 5.6.2 mitigates the vulnerability. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H confirms network-based exploitation without authentication.

Official resources

2024-05-30