LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands.
The vulnerability classified as CWE-88 (argument injection/injection into argument) allows an attacker to inject malicious arguments or commands in the location where the NetBox application processes input data and passes it to system calls or external processes. An attacker with access to an authenticated session can prepare an appropriate request containing a malicious payload that will be executed with the privileges of the application process at the operating system level.
Successful exploitation of the vulnerability enables an attacker to execute arbitrary system commands on the NetBox server, which may lead to complete system takeover, theft of configuration data, and disruption of physical access control infrastructure operations.
Patches available from the manufacturer should be applied according to references (Carrier security advisory CARR-PSA-2024-01 and CISA bulletin ICS-Advisory ICSA-24-151-01). It is recommended to update LenelS2 NetBox system to a version newer than 5.6.1 and restrict access to the administrative interface exclusively to trusted networks and authorized users.
Honeywell LenelS2 NetBox — versions up to 5.6.1 inclusive
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHoneywell Lenels2 Netbox
APPHoneywell< 5.6.2
Related vulnerabilities
Nieuwierzytelniony RCE w Honeywell LenelS2 NetBox (command injection)
LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in v...
Honeywell IQ4x — brak uwierzytelnienia w fabrycznym HMI (CWE-306)
OS Command Injection w Honeywell MB-Secure i MB-Secure PRO (privilege abuse)
Nieautoryzowana modyfikacja plików w Honeywell ControlEdge UOC i VirtualUOC