CVE-2024-2421: LenelS2 NetBox Improper Neutralization of Special Elements
Published May 30, 2024
·Updated
LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands with elevated permissions.
Affected Software
2 affected components
LenelS2 NetBox<=5.6.1
Honeywell Lenels2 Netbox<5.6.2
Remediation
Information
LenelS2 advises customers to apply to the updated version of NetBox 5.6.2 or newer via the LenelS2 Partner Center. Please get in touch with your support channel partner for instructions.
Event History
May 30, 2024
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-2421?
CVE-2024-2421 is considered critical due to its potential to allow unauthenticated remote code execution.
2
How do I fix CVE-2024-2421?
To fix CVE-2024-2421, update LenelS2 NetBox to version 5.6.2 or later.
3
Who is affected by CVE-2024-2421?
CVE-2024-2421 affects users of LenelS2 NetBox versions 5.6.1 and earlier.
4
What types of attacks can exploit CVE-2024-2421?
CVE-2024-2421 can be exploited to execute malicious commands remotely with elevated permissions.
5
Is there a workaround for CVE-2024-2421?
Currently, the recommended action for CVE-2024-2421 is to perform the update, as no known workarounds exist.