PatchSiren cyber security CVE debrief
CVE-2024-2420 LenelS2 CVE debrief
CVE-2024-2420 is a critical authentication bypass vulnerability in LenelS2 NetBox, an access control and event monitoring system used in physical security environments. The vulnerability stems from hard-coded credentials present in versions prior to and including 5.6.1, enabling unauthenticated attackers to gain unauthorized access to affected systems. Published by CISA on May 30, 2024, this vulnerability carries a CVSS 3.1 score of 9.8 (Critical), reflecting its network-exploitable nature, low attack complexity, and high impact on confidentiality, integrity, and availability. The affected product is LenelS2 NetBox versions below 5.6.2. Carrier has released NetBox version 5.6.2 to address this issue. Organizations should prioritize upgrading to the patched version and consult the NetBox hardening guide for secure deployment practices.
- Vendor
- LenelS2
- Product
- NetBox
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-05-30
- Original CVE updated
- 2024-05-30
- Advisory published
- 2024-05-30
- Advisory updated
- 2024-05-30
Who should care
Organizations using LenelS2 NetBox for physical access control and security event monitoring, particularly in critical infrastructure, commercial facilities, and enterprise environments. Security teams responsible for ICS/OT security, facility managers, and physical security administrators should prioritize this patch.
Technical summary
LenelS2 NetBox versions prior to 5.6.2 contain hard-coded credentials that allow attackers to bypass authentication requirements entirely. The vulnerability is remotely exploitable over the network without any user interaction or privileges. Successful exploitation grants attackers full administrative access to the access control and event monitoring system, compromising physical security operations. The CVSS 3.1 score of 9.8 reflects critical impact across confidentiality, integrity, and availability dimensions. Carrier released NetBox 5.6.2 as the definitive fix.
Defensive priority
critical
Recommended defensive actions
- Upgrade LenelS2 NetBox to version 5.6.2 by contacting your authorized installer.
- Follow the NetBox hardening guide available in the built-in help menu for secure deployment.
- Review and apply CISA's ICS recommended practices for industrial control system security.
- Monitor for unauthorized access attempts in NetBox audit logs.
- Restrict network access to NetBox management interfaces to authorized administrative hosts only.
Evidence notes
CISA published advisory ICSA-24-151-01 on May 30, 2024, confirming hard-coded credentials in NetBox versions ≤5.6.1. The advisory specifies that version 5.6.2 mitigates the vulnerability. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H confirms network-based exploitation without authentication.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-2420 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-2420
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-2420 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-2420
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-151-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-151-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.