PT-2024-3980 · Lenels2 · Lenels2 Netbox

Claroty Team82

+1

·

Published

2024-03-13

·

Updated

2026-02-02

·

CVE-2024-2420

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LenelS2 NetBox versions prior to and including 5.6.1
Description The issue is related to hardcoded credentials in the LenelS2 NetBox access control and event monitoring system. This allows an attacker to bypass authentication requirements. The exploitation of this issue may enable a remote attacker to circumvent the authentication procedure.
Recommendations For versions prior to and including 5.6.1, update to a version later than 5.6.1 to resolve the issue. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-04395
CVE-2024-2420

Affected Products

Lenels2 Netbox