CVE-2024-2658General

HIGHCVSS 8.5 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.

7.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 12 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 6 classified signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 3 mentions (2026-07-01); latest day: 1
  • 12 total mentions across 8 days

Deep dive

Activity timeline12 mentions / 8d
01223Mentions · 2026-06-26: 1Mentions · 2026-06-28: 1Mentions · 2026-06-29: 1Mentions · 2026-07-01: 3Mentions · 2026-07-02: 3Mentions · 2026-07-03: 1Mentions · 2026-07-04: 1Mentions · 2026-07-24: 1PoC Mentioned / Linked · 2026-07-04: 1Exploit Tool / Code · 2026-07-04: 1Active Exploitation · 2026-07-02: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-04: 106-2606-2806-2907-0107-0207-0307-0407-24
Signal classification4 categories
General
650.0%
Disclosure
433.3%
Active Exploitation
18.3%
Exploit
18.3%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-06-261
General1
2026-06-281
General1
2026-06-291
Disclosure1
2026-07-013
General3
2026-07-023
Active Exploitation1Disclosure2
2026-07-031
Disclosure1
2026-07-041
Exploit1
2026-07-241
General1
Full discourse12 posts
  • blackorbird@blackorbird
    Disclosure

    #OT The CVE-2024-2658 vulnerability was discovered in 2024 within the FlexNet Publisher component of the Schneider Electric Floating License Manager. https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436/ https://t.co/s5AnbMuHc8

    Post summary

    The text announces the discovery of CVE-2024-2658 in Schneider Electric’s FlexNet Publisher, referencing a SecureList article but providing no further technical or exploitation details.

    0502052.6K
    43.6K followersView on X
  • Eugene Kaspersky@e_kaspersky
    Disclosure

    Vulnerability CVE-2024-2658 in the FlexNet Publisher component used in Schneider Electric's Floating License Manager software poses a serious threat to industrial enterprises. It allows hackers to both escalate privileges to the SYSTEM level, and attack industrial network nodes. Read our analysis of how this exploitation method works, and how to detect the threat promptly: https://kas.pr/7woz

    Post summary

    The post announces CVE-2024-2658 affecting Schneider Electric's Floating License Manager, noting privilege escalation to SYSTEM and industrial network attack potential, but provides no PoC, exploit tool, active usage, or patch information.

    0801472.4K
    178.7K followersView on X
  • Kaspersky@kaspersky
    General

    The CVE-2024-2658 vulnerability was discovered in 2024 within the FlexNet Publisher component of the Schneider Electric Floating License Manager. This software handles license management across various Schneider Electric products used for comprehensive industrial automation ranging from PLC programming to centralized control room implementation. In the report, we break down how a single flaw can jeopardize an entire industrial facility, how to detect it on your workstations, and how to minimize the risks. See more > https://kas.pr/9nos #CyberSecurity #OTSecurity #IndustrialSecurity #ICS #ThreatIntelligence

    Post summary

    The post announces the discovery of CVE‑2024‑2658 in Schneider Electric’s FlexNet Publisher component, explains its potential industrial impact, and directs readers to an external report for more details.

    021711.9K
    312.4K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    General

    Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet warns of a Schneider Electric license manager vulnerability (CVE-2024-2658) that could expose industrial facilities, but offers no PoC, exploitation details, patches, or technical specifics.

    02012990
    195.0K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (June 27 - July 04, 2026) 1⃣. Bad Epoll (CVE-2026-46242) https://github.com/J-jaeyoung/bad-epoll // race-condition UaF in the Linux kernel's epoll subsystem 2⃣. Mitigated API authentication bypass for python*org download metadata https://blog.python.org/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org 3⃣. Exploits for 23 unpatched vulnerabilities in FFmpeg, VLC, Firefox, Docker, PHP, OpenVPN, nmap, libssh2, nghttp2, and 7zip have been disclosed https://github.com/bikini/exploitarium 4⃣. Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436 5⃣. Apple Hide My Email Vulnerability https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses 6⃣. DNS Tricks to Load Malware into Cloned Repository https://0din.ai/blog/clone-this-repo-and-i-own-your-machine 7⃣. Google Gemini CLI Vulnerability https://github.com/advisories/GHSA-jj69-4grx-fqj5 // CVE-2026-12537 8⃣. Apache MINA Deserialization Bypass to RCE https://blog.securelayer7.net/cve-2026-42779-apache-mina-deserialization-rce // CVE-2026-42779 affects Apache MINA versions 2.1.0 - 2.1.11 and 2.2.0 - 2.2.6 9. CyberPocket makes cybersecurity alerts easy to understand. Paste an alert, upload a screenshot, or submit a security message, and CyberPocket turns confusing technical details into a clear summary, risk level, next steps, and client-ready ticket notes. Built for individuals, students, IT teams, MSPs, MSSPs, and SOC analysts, CyberPocket helps you triage faster, learn smarter, and respond with confidence. Visit http://cyberpocket.org and turn confusing alerts into clear action. 10. Build smarter AI agents faster. http://www.GenieBot.Store helps you generate production-ready AI agent system prompts for Claude, ChatGPT, OpenAI, Gemini, Mistral, Llama, and custom LLMs. Choose your tier, describe your business, select your platform, and receive a customized prompt built to help your AI agent think, respond, and operate with purpose.

    Post summary

    The update lists several CVEs with publicly available PoC or exploitation code and technical details, but it does not assert active exploitation or confirmed patch availability.

    00021407
    3.4K followersView on X
  • Nicolas Krassas@Dinosn
    General

    Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436/

    Post summary

    The post flags a Schneider Electric software vulnerability (CVE‑2024‑2658) as a potential risk to industrial facilities but provides no technical, exploit, or mitigation details.

    010022.2K
    160.8K followersView on X
  • Евгений Касперский@e_kaspersky_ru
    Disclosure

    Уязвимость CVE-2024-2658 в компоненте FlexNet Publisher, используемом в программном обеспечении Schneider Electric Floating License Manager, – серьезная угроза для промышленных предприятий, она позволяет хакерам повысить привилегии до уровня SYSTEM и атаковать узлы промышленной сети. Читайте наш разбор, как работает этот метод эксплуатации и как своевременно обнаружить угрозу: https://kas.pr/t7iz

    Post summary

    CVE-2024-2658 is a privilege‑escalation flaw in FlexNet Publisher used by Schneider Electric’s Floating License Manager, capable of giving attackers SYSTEM level access on industrial network nodes.

    01010292
    24.2K followersView on X
  • Dr.Philippe Vynckier, CISSP - Influencer@PVynckier
    General

    CVE-2024-2658 vulnerability in Schneider Electric software: risks to industrial control systems | Securelist https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436/

    Post summary

    The text announces the CVE-2024-2658 vulnerability in Schneider Electric software, highlighting potential industrial control system risks, but provides no additional technical details, PoC, or exploitation information.

    01010103
    24.1K followersView on X
  • ShiftSix Security@Shift6Security
    General

    Not the PLC firmware. The license manager. CVE-2024-2658 in Schneider Electric's software licensing tool per Kaspersky Securelist. OT risk hides in the components nobody thinks to audit.

    Post summary

    The text briefly notes the existence of CVE-2024-2658 in Schneider Electric's license manager without providing exploitation details, patches, or technical information.

    0100064
    1.8K followersView on X
  • omvapt@omvapt
    Disclosure

    CVE-2024-2658 #vulnerability in #Schneider_Electric #software: risks to #industrial_control_systems https://ift.tt/Fg9uVGE https://t.co/snZw7AOrvJ

    Post summary

    The tweet announces CVE‑2024‑2658 as a vulnerability in Schneider Electric software that poses risks to industrial control systems, but it offers no technical details, PoC, or remediation guidance.

    0000048
    389 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2024-2658 in Schneider Electric's License Manager can escalate from local user to SYSTEM privileges, enabling lateral movement across industrial networks. Runtime segmentation helps contain post-compromise activity in OT environments. #IndustrialSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/schneider-electric-cve-2024-2658-vulnerability

    Post summary

    The post confirms that CVE-2024-2658 has been actively exploited to elevate privileges from local users to SYSTEM, facilitating lateral movement in Schneider Electric industrial networks.

    0000046
    1.9K followersView on X
  • Shah Sheikh@shah_sheikh
    General

    Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk: Analysis of CVE-2024-2658 as found in Schneider Electric's Floating License Manager. Discover how this FlexNet Publisher vulnerability… https://securelist.com/tr/schneider-electric-cve-2024-2658-vulnerability/120436/?utm_source=dlvr.it&utm_medium=twitter https://t.co/E1jMYEWxAF

    Post summary

    The tweet references an analysis of CVE-2024-2658 in Schneider Electric's Floating License Manager but provides no PoC, exploit code, patch info, or evidence of active exploitation.

    0000051
    2.3K followersView on X

Explore more