CVE-2024-2658
published 2025-01-30CVE-2024-2658: A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent…
PriorityP343high8.5CVSS 4.0
AVLACLATNPRLUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.42%
34.0th percentile
A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| flexera | flexnet_publisher | < 2024 R1 (11.19.6.0) | 2024 R1 (11.19.6.0) |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric EcoStruxure (Update D)
cisa_ics·2026-04-02·CVSS 8.5
[HIGH] Schneider Electric EcoStruxure (Update D)
ICS Advisory
##
Schneider Electric EcoStruxure (Update D)
Last RevisedApril 02, 2026
Alert CodeICSA-25-037-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Schneider Electric is aware of a vulnerability disclosed on Revenera FlexNet Publisher component. Many vendors, including Schneider Electric, embed Revenera FlexNet Publisher in their offers. Failure to apply the remediation/mitigations provided below may risk a local privilege escalation, which could lead to the execution of a malicious DLL with elevated privilege.
The following versions of Schneider Electric EcoStruxure (Update D) are affected:
- EcoStruxure™ Control Expert <16.2 (CVE-2024-2658)
- EcoStruxure™ Process Expert <2023_v4.8.0.571
GHSA
GHSA-2795-pjw4-5495: A misconfiguration in lmadmin
ghsa_unreviewed·2025-01-30
CVE-2024-2658 [HIGH] CWE-427 GHSA-2795-pjw4-5495: A misconfiguration in lmadmin
A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.
No detection rules found.
No public exploits indexed.
Securelist
Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk
blogs_securelist·2026-06-26·CVSS 8.5
CVE-2024-2658 [HIGH] Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk
## Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk
posted 26 Jun 2026
minute read
Table of Contents
About the vulnerability
The role of FlexNet Publisher in Schneider Electric FLM
The exploit path
Mitigating CVE-2024-2658
Detection with Kaspersky solutions
Conclusion
## About the vulnerability
The CVE-2024-2658 vulnerability was discovered in 2024 within the FlexNet Publisher component of the Schneider Electric Floating License Manager. This software handles license management across various Schneider Electric products used for comprehensive industrial automation ranging from PLC programming to centralized control room implementation. Below, we break down how a single flaw can jeopardize an entire industrial facil
Wiz
CVE-2019-25313 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2019-25313 [CRITICAL] CVE-2019-25313 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2019-25313 :
FlexNet Publisher vulnerability analysis and mitigation
FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new local admin account with a predefined password.
Source : NVD
## 5.1
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
FlexNet Publisher
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:flexerasoftware:flexnet_publisher
2025-01-30
Published