CVE-2024-2420
Severity CVSS v4.0:
HIGH
Type:
CWE-259
Use of Hard-coded Password
Publication date:
30/05/2024
Last modified:
02/02/2026
Description
LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.
Impact
Base Score 4.0
8.80
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:honeywell:lenels2_netbox:*:*:*:*:*:*:*:* | 5.6.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



