CVE-2024-2422: LenelS2 NetBox Improper Neutralization of Argumented Delimiters
Published May 30, 2024
·Updated
LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands.
Affected Software
2 affected components
LenelS2 NetBox<=5.6.1
Honeywell Lenels2 Netbox<5.6.2
Remediation
Information
LenelS2 advises customers to apply to the updated version of NetBox 5.6.2 or newer via the LenelS2 Partner Center. Please get in touch with your support channel partner for instructions.
Event History
May 30, 2024
CVE Published
via MITRE·05:26 PM
Data Sourced
via MITRE·05:26 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-2422?
CVE-2024-2422 is considered critical due to its potential for authenticated remote code execution.
2
How do I fix CVE-2024-2422?
To fix CVE-2024-2422, upgrade LenelS2 NetBox to version 5.6.2 or later.
3
Who is affected by CVE-2024-2422?
CVE-2024-2422 affects users of LenelS2 NetBox versions prior to and including 5.6.1.
4
What type of vulnerability is CVE-2024-2422?
CVE-2024-2422 is an authenticated remote code execution vulnerability.
5
What can attackers do with CVE-2024-2422?
Attackers can execute arbitrary malicious commands on the affected LenelS2 NetBox system.