Summary
A Denial of Service vulnerability was discovered, on Certain message protocol in FlexNet Publisher's lmadmin 11.16.6. Please see the Symptoms section for more details.
If you do not distribute lmadmin to your customers, there is no further action on your part. If you do, you must distribute to those same customers the security update mentioned in the Resolution section of this article.
Symptoms
**** Only the following information is permitted to be distributed to users of products enabled with FlexNet Publisher:
- CVE number (if available)
- CWE ID
- CVSS scores
- Any publicly available information
****
Certain message protocol in FlexNet Publisher lmadmin is unable to validate its message data. Such messages can cause lmadmin to crash. This vulnerability has been assigned the ID of CVE-2020-12080. The CVSSv3 base score for this vulnerability is 6.5; that is, medium severity.
Resolution
The FlexNet Publisher 11.17.0 and later address the security vulnerability and will be available on Flexera’s Product and License Center. We advise all FlexNet Publisher customers update lmadmin.exe to FlexNet Publisher 11.17.0 or later. As good practice, we advise customers to expose lmadmin to only a trusted network. This will reduce the attack vector to only those attackers who have access to that trusted network.
Additional Information
For identifying this vulnerability and disclosing it to Flexera under a responsible disclosure process, we'd like to thank Tenable, Inc.
Related Documents
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12080
Related Articles
CVE-2019-8960 Remediated in FlexNet Publisher 21Number of Views CVE-2018-20034 remediated in FlexNet Publisher 8Number of Views CVE-2018-20033 Remediated in FlexNet Publisher 8Number of Views CVE-2019-8962 remediated in FlexNet Publisher 6Number of Views CVE-2018-20031 Remediated in FlexNet Publisher 11Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago