LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands with elevated permissions.
The vulnerability classified as CWE-78 (OS Command Injection) allows an unauthorized attacker to inject and execute arbitrary system commands over the network without authentication. Malicious commands are executed with elevated privileges, meaning the attacker gains broad access to the device's operating system. The lack of user interaction requirement and the absence of special prerequisite conditions make this vulnerability particularly dangerous in network environments.
An attacker can take full control of the LenelS2 NetBox system by executing arbitrary commands with elevated privileges, which may lead to violations of confidentiality, integrity, and availability of the access control and event monitoring system.
The LenelS2 NetBox system should be updated immediately to a version higher than 5.6.1. Detailed instructions are available in the manufacturer's guide (CARR-PSA-2024-01) and in the ICS-CERT message ICSA-24-151-01. Until the patch is implemented, it is recommended to isolate the device from untrusted network segments and restrict network access to the system using a firewall.
Honeywell LenelS2 NetBox in versions up to and including 5.6.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHoneywell Lenels2 Netbox
APPHoneywell< 5.6.2
Related vulnerabilities
Uwierzytelniony RCE w LenelS2 NetBox (wersje do 5.6.1 włącznie)
LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in v...
Honeywell IQ4x — brak uwierzytelnienia w fabrycznym HMI (CWE-306)
OS Command Injection w Honeywell MB-Secure i MB-Secure PRO (privilege abuse)
Nieautoryzowana modyfikacja plików w Honeywell ControlEdge UOC i VirtualUOC