CVE-2024-2658

Published Jan 30, 2025

Last updated 4 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-2658 describes a misconfiguration within the `lmadmin.exe` component of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0). This flaw allows the OpenSSL configuration file to be loaded from a directory that does not exist. An unauthorized, locally authenticated user with low privileges can exploit this by creating the non-existent directory and placing a specially crafted `openssl.conf` file within it. This action can lead to the execution of a malicious Dynamic-Link Library (DLL) with elevated privileges on the affected system.

Description
A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.
Source
PSIRT-CNA@flexerasoftware.com
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

PSIRT-CNA@flexerasoftware.com
CWE-427

Social media

Hype score
Not currently trending
  1. Not the PLC firmware. The license manager. CVE-2024-2658 in Schneider Electric's software licensing tool per Kaspersky Securelist. OT risk hides in the components nobody thinks to audit.

    @Shift6Security

    24 Jul 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-2658 #vulnerability in #Schneider_Electric #software: risks to #industrial_control_systems https://t.co/NYmRA3dmYv https://t.co/snZw7AOrvJ

    @omvapt

    3 Jul 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. #OT The CVE-2024-2658 vulnerability was discovered in 2024 within the FlexNet Publisher component of the Schneider Electric Floating License Manager. https://t.co/1AROdpF7pM https://t.co/s5AnbMuHc8

    @blackorbird

    2 Jul 2026

    2087 Impressions

    4 Retweets

    18 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  4. Vulnerability CVE-2024-2658 in the FlexNet Publisher component used in Schneider Electric's Floating License Manager software poses a serious threat to industrial enterprises. It allows hackers to both escalate privileges to the SYSTEM level, and attack industrial network nodes.

    @e_kaspersky

    2 Jul 2026

    1921 Impressions

    6 Retweets

    13 Likes

    6 Bookmarks

    1 Reply

    0 Quotes

  5. TRC analysis shows attackers exploiting CVE-2024-2658 in Schneider Electric's License Manager can escalate from local user to SYSTEM privileges, enabling lateral movement across industrial networks. Runtime segmentation helps contain post-compromise activity in OT environments.

    @aviatrixtrc

    2 Jul 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk: Analysis of CVE-2024-2658 as found in Schneider Electric's Floating License Manager. Discover how this FlexNet Publisher vulnerability… https://t.co/k2yfbma8j3 htt

    @shah_sheikh

    1 Jul 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-2658 vulnerability in Schneider Electric software: risks to industrial control systems | Securelist https://t.co/5pgiItga7J

    @PVynckier

    28 Jun 2026

    96 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. The CVE-2024-2658 vulnerability was discovered in 2024 within the FlexNet Publisher component of the Schneider Electric Floating License Manager. This software handles license management across various Schneider Electric products used for comprehensive industrial automation https

    @kaspersky

    26 Jun 2026

    1444 Impressions

    1 Retweet

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Actively exploited CVE : CVE-2024-2658

    @transilienceai

    13 Feb 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. Actively exploited CVE : CVE-2024-2658

    @transilienceai

    10 Feb 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Actively exploited CVE : CVE-2024-2658

    @transilienceai

    9 Feb 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. Actively exploited CVE : CVE-2024-2658

    @transilienceai

    9 Feb 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. Actively exploited CVE : CVE-2024-2658

    @transilienceai

    7 Feb 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes