CRITICAL🇵🇱 Wersja polska

CVE-2024-2421

CVSS 9.3v4.0pub. 2024-05-30upd. 2026-02-02

LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands with elevated permissions.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-78 (OS Command Injection) allows an unauthorized attacker to inject and execute arbitrary system commands over the network without authentication. Malicious commands are executed with elevated privileges, meaning the attacker gains broad access to the device's operating system. The lack of user interaction requirement and the absence of special prerequisite conditions make this vulnerability particularly dangerous in network environments.

Impact

An attacker can take full control of the LenelS2 NetBox system by executing arbitrary commands with elevated privileges, which may lead to violations of confidentiality, integrity, and availability of the access control and event monitoring system.

Mitigation & patch

The LenelS2 NetBox system should be updated immediately to a version higher than 5.6.1. Detailed instructions are available in the manufacturer's guide (CARR-PSA-2024-01) and in the ICS-CERT message ICSA-24-151-01. Until the patch is implemented, it is recommended to isolate the device from untrusted network segments and restrict network access to the system using a firewall.

Who is affected

Honeywell LenelS2 NetBox in versions up to and including 5.6.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Honeywell Lenels2 Netbox

    APP
    Honeywell
    < 5.6.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2024-2422CRITICAL9.3PL ✓same product

Uwierzytelniony RCE w LenelS2 NetBox (wersje do 5.6.1 włącznie)

CVE-2024-2420HIGH8.8same product

LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in v...

CVE-2026-3611CRITICAL10.0PL ✓same vendor

Honeywell IQ4x — brak uwierzytelnienia w fabrycznym HMI (CWE-306)

CVE-2025-2605CRITICAL9.9PL ✓same vendor

OS Command Injection w Honeywell MB-Secure i MB-Secure PRO (privilege abuse)

CVE-2023-5389CRITICAL9.1PL ✓same vendor

Nieautoryzowana modyfikacja plików w Honeywell ControlEdge UOC i VirtualUOC