← Vulnerability feed

Vulnerability record · CVE-2018-20031 · published 21 March 2019

CVE-2018-20031: Flexera flexnet publisher vulnerability

Flexera · Flexnet Publisher

A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

7.5 CVSS 3.1 High EPSS 2.2% · top 17.7%
7.5CVSS 3.1 base score, v2 5.0
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-20031 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-0235glibc gethostbyname heap buffer overflow (GHOST)CVE-2015-0235 is a heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2 and other 2.x versions before 2.18. It is reach…EPSS 95%analysed9.8CVE-2021-21783Genivia gsoap integer overflow vulnerabilityA code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead t…EPSS 5.3%9.8CVE-2018-20033Flexera flexnet publisher allocation without limits vulnerabilityA Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote a…EPSS 3.7%8.6CVE-2020-10878Perl integer overflow vulnerabilityPerl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could l…EPSS 4.9%8.2CVE-2020-10543Perl integer overflow vulnerabilityPerl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.EPSS 11%7.5CVE-2019-8963Flexera flexnet publisher vulnerabilityA Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the…EPSS 0.65%7.5CVE-2020-12080Flexera flexnet publisher improper input validation vulnerabilityA Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited…EPSS 2.1%7.5CVE-2020-12081Flexera flexnet publisher vulnerabilityAn information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0.2. The web portal link can be used to access to …EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2018-20031), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.