LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.
References
| Link | Resource |
|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-24-151-01 | US Government Resource Vendor Advisory |
| https://www.corporate.carrier.com/Images/CARR-PSA-2024-01-NetBox_tcm558-227956.pdf | Broken Link |
| https://www.cisa.gov/news-events/ics-advisories/icsa-24-151-01 | US Government Resource Vendor Advisory |
| https://www.corporate.carrier.com/Images/CARR-PSA-2024-01-NetBox_tcm558-227956.pdf | Broken Link |
Configurations
History
02 Feb 2026, 13:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-151-01 - US Government Resource, Vendor Advisory | |
| References | () https://www.corporate.carrier.com/Images/CARR-PSA-2024-01-NetBox_tcm558-227956.pdf - Broken Link | |
| CPE | cpe:2.3:a:honeywell:lenels2_netbox:*:*:*:*:*:*:*:* | |
| First Time |
Honeywell
Honeywell lenels2 Netbox |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
21 Nov 2024, 09:09
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-151-01 - | |
| References | () https://www.corporate.carrier.com/Images/CARR-PSA-2024-01-NetBox_tcm558-227956.pdf - | |
| Summary |
|
30 May 2024, 18:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-05-30 18:15
Updated : 2026-02-02 13:14
NVD link : CVE-2024-2420
Mitre link : CVE-2024-2420
CVE.ORG link : CVE-2024-2420
JSON object : View
Products Affected
honeywell
- lenels2_netbox
CWE
CWE-259
Use of Hard-coded Password
