Elevated Privileges Vulnerability in FlexNet Manager Suite by Flexera Software
CVE-2017-6885

9.8CRITICAL

Key Information:

Vendor
CVE Published:
16 May 2017

What is CVE-2017-6885?

A vulnerability exists in FlexNet Manager Suite, specifically impacting the FlexNet Inventory Agent and FlexNet Beacon. The flaw arises from improper handling of certain external commands and services. This weakness may allow an attacker to exploit the system, leading to unauthorized escalation of privileges, thus potentially compromising the integrity and confidentiality of affected systems. Proper patches and mitigations should be applied to ensure the security of the software.

Affected Version(s)

FlexNet Manager Suite 2017 prior to 2017 R1

FlexNet Manager Suite 2014 R3 through 2016 R1 SP1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.