Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Flexera

Flexera Vendor Cyber Rating & Cyber Score

flexera.com

Flexera helps organizations understand and maximize the value of their technology, saving billions of dollars in wasted spend. Powered by the Flexera Technology Intelligence Platform, our award-winning IT asset management, FinOps and SaaS management solutions provide comprehensive visibility and actionable insights on an organization’s entire IT ecosystem. This intelligence enables IT, finance, procurement and cloud teams to address skyrocketing costs, optimize spend, mitigate risk and identify opportunities to create positive business outcomes. More than 50,000 global organizations rely on Flexera and its Technopedia reference library, the largest repository of technology asset data. Learn more at flexera.com.


Flexera A.I CyberSecurity Scoring

Flexera
Company Information
Website:https://flexera.com
Employees number:2,091
Number of followers:153,949
NAICS:5112
Industry Type:Software Development
Homepage:flexera.com
Flexera Risk Score (AI oriented)
Between 750 and 799
logo
FlexeraSoftware Development
Updated:
26/06/2026
766/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Flexera Global Score (TPRM)
xxxx
logo
FlexeraSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

FlexeraFair
Current Score
766Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
766Before Incident
SEPTEMBER 2026
766Before Incident
AUGUST 2026
766Before Incident
JULY 2026
766Before Incident
JUNE 2026
766Before Incident
MAY 2026
766Before Incident
APRIL 2026
766Before Incident
MARCH 2026
766Before Incident
FEBRUARY 2026
766Before Incident
JANUARY 2026
766Before Incident
DECEMBER 2025
765Before Incident
NOVEMBER 2025
765Before Incident
JANUARY 2024
765Before Incident
Vulnerability
01 Jan 2024 • Flexera
Schneider Electric and Flexera: CVE-2024-2658 vulnerability in Schneider Electric software: risks to industrial control systems

Critical Privilege Escalation Vulnerability in Schneider Electric Floating License Manager (CVE-2024-2658)

763After Incident
CRITICAL-2
FLESCH1782484233
Critical Privilege Escalation Vulnerability in Schneider Electric Floating License Manager (CVE-2024-2658) A high-severity vulnerability (CVE-2024-2658) has been identified in Schneider Electric’s Floating License Manager (FLM), specifically within the FlexNet Publisher component a third-party licensing library integrated into industrial automation software. The flaw, classified as CWE-427 (Uncontrolled Search Path Element), allows a local non-administrative user to escalate privileges to NT AUTHORITY\SYSTEM, granting full control over affected systems. ### Vulnerability Mechanics The issue stems from lmadmin.exe, a core licensing service in Schneider Electric FLM, which references a hardcoded OpenSSL configuration file path (`C:\cygwin\home\nightly\LMADMI~1.4\tier1\lmadmin\contrib\openssl\_RELEA~1\openssl\openssl.cnf`). Due to default Windows NTFS permissions, any authenticated user can recreate this directory structure and place a malicious openssl.cnf file containing a dynamic_path parameter pointing to a rogue DLL. When lmadmin.exe (running under NT AUTHORITY\LOCAL SERVICE) restarts via reboot, service restart, or other triggers it loads the attacker-controlled DLL, executing arbitrary code in the service’s context. Exploiting SeImpersonatePrivilege, an attacker can further escalate to NT AUTHORITY\SYSTEM, enabling: - Full system compromise (configuration files, sensitive data, stored credentials). - Lateral movement across industrial networks (engineering workstations, PLCs, SCADA systems). - Disruption of license services, impacting critical automation software availability. ### Affected Systems & Scope - Software: Schneider Electric FLM (versions prior to 3.0.0.0) using FlexNet Publisher ≤11.19.6.0. - Environment: Industrial automation deployments (PLC programming, SCADA, control rooms). - Attack Vector: Local access required; no remote exploitation possible without prior foothold. ### Detection & Mitigation - Detection: Kaspersky Industrial CyberSecurity (KICS) flags vulnerable versions and monitors exploitation attempts, including rogue configuration file creation and DLL loading. - Mitigation Steps: - Upgrade to Schneider Electric FLM 3.0.0.0 or later. - Restrict directory permissions on `C:\cygwin` to deny write access for Authenticated Users. - Isolate FLM on dedicated servers with strict access controls. - Remove FLM if floating licenses are unnecessary, opting for machine-bound licensing. ### Impact Successful exploitation could lead to complete industrial control system (ICS) compromise, enabling attackers to manipulate automation processes, exfiltrate sensitive data, or disrupt operations. The vulnerability underscores risks in third-party dependencies and hardcoded path vulnerabilities in critical infrastructure software.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Data Compromised: Sensitive data, stored credentials, configuration filesSystems Affected: Industrial automation software, PLCs, SCADA systems, engineering workstationsDowntime: Potential disruption of license services and automation software availabilityOperational Impact: Full system compromise, lateral movement across industrial networks, disruption of critical automation processesBrand Reputation Impact: Potential reputational damage due to critical infrastructure vulnerability
DATA BREACH
Type Of Data Compromised: Sensitive data, stored credentials, configuration filesSensitivity Of Data: High (industrial control system configurations, credentials)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Flexera ?
?
What was Flexera's A.I Rankiteo Cyber Score in September 2026 ?
?
What was Flexera's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Flexera's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Flexera's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Flexera's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Flexera's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Flexera's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Flexera's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Flexera's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Flexera's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Flexera's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on Flexera's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Flexera ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Flexera's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?