CRITICAL🇵🇱 Wersja polska

CVE-2024-2422

CVSS 9.3v4.0pub. 2024-05-30upd. 2026-02-02

LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-88 (argument injection/injection into argument) allows an attacker to inject malicious arguments or commands in the location where the NetBox application processes input data and passes it to system calls or external processes. An attacker with access to an authenticated session can prepare an appropriate request containing a malicious payload that will be executed with the privileges of the application process at the operating system level.

Impact

Successful exploitation of the vulnerability enables an attacker to execute arbitrary system commands on the NetBox server, which may lead to complete system takeover, theft of configuration data, and disruption of physical access control infrastructure operations.

Mitigation & patch

Patches available from the manufacturer should be applied according to references (Carrier security advisory CARR-PSA-2024-01 and CISA bulletin ICS-Advisory ICSA-24-151-01). It is recommended to update LenelS2 NetBox system to a version newer than 5.6.1 and restrict access to the administrative interface exclusively to trusted networks and authorized users.

Who is affected

Honeywell LenelS2 NetBox — versions up to 5.6.1 inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Honeywell Lenels2 Netbox

    APP
    Honeywell
    < 5.6.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-2421CRITICAL9.3PL ✓same product

Nieuwierzytelniony RCE w Honeywell LenelS2 NetBox (command injection)

CVE-2024-2420HIGH8.8same product

LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in v...

CVE-2026-3611CRITICAL10.0PL ✓same vendor

Honeywell IQ4x — brak uwierzytelnienia w fabrycznym HMI (CWE-306)

CVE-2025-2605CRITICAL9.9PL ✓same vendor

OS Command Injection w Honeywell MB-Secure i MB-Secure PRO (privilege abuse)

CVE-2023-5389CRITICAL9.1PL ✓same vendor

Nieautoryzowana modyfikacja plików w Honeywell ControlEdge UOC i VirtualUOC