Database/Control plane, storage & DevOps
LenelS2 NetBox access control and event monitoring system (<=5.6.1): Unauthenticated remote code execution
Impact
Unauthenticated remote code execution with elevated privileges, plus hardcoded credentials that bypass authentication outright, plus a second authenticated RCE. NetBox is the head-end - the system that holds the cardholder database, the access rules, the door schedules and the event log for the whole site. Owning it is strictly more powerful than owning a single panel: an attacker can grant themselves a credential that works on every door, schedule doors to unlock, and erase the events showing they did. Physical entry to the hall and the cage follows, and from inside the cage the attacker reaches drives holding customer data and model weights, server console ports, and the out-of-band management switch that fronts every BMC in the row. For a bare-metal GPU provider, an attacker with head-end control can also target one specific tenant's cage on demand, which turns a security incident into a customer-trust and contractual event. Hardcoded credentials mean the exposure predates any breach you can detect.
Who can reach it
Unauthenticated over the network for the RCE and the hardcoded-credential bypass. NetBox is a web-managed appliance; sites routinely make it reachable from the corporate network so security staff can administer badges, and internet-exposed NetBox instances have been observed. Any of those makes this a direct, no-credential path from outside to physical door control.
What to do
Upgrade NetBox past 5.6.1 to the fixed release per Carrier's advisory - a head-end software update in a normal change window, no door hardware touched, so there is no operational excuse to defer. Because hardcoded credentials were present, patching alone does not establish trust: rotate all system and integration credentials, audit the cardholder database and access rules against a known-good export, review the event log for gaps, and check whether any credentials were added during the exposure window. Then remove NetBox from any internet-facing or general corporate reachability and put it behind a jump host with MFA.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.