CVE-2024-2658 vulnerability in Schneider Electric software: risks to industrial control systems
Summary
The article explains CVE-2024-2658 in Schneider Electric Floating License Manager and the FlexNet Publisher component it embeds. A local attacker can place a rogue OpenSSL configuration file at a hardcoded path and force the service to load a malicious DLL. That can lead to code execution in the service context and, under some conditions, privilege escalation to NT AUTHORITY\SYSTEM. The piece also outlines mitigation steps such as upgrading to version 3.0.0.0 or later, tightening folder permissions, and removing the software where floating licenses are not needed.
Classifications
industries
No industries detected
applications
Web and Content Management
AI Classifications
Labels
Software Asset Management
SaaS Management
Cloud Cost Management