PatchSiren cyber security CVE debrief
CVE-2017-5571 Flexerasoftware CVE debrief
CVE-2017-5571 is an open redirect vulnerability in the lmadmin component of Flexera FlexNet Publisher 11.14.1 and earlier. According to the NVD record, this issue can let a remote attacker redirect users to arbitrary websites and support phishing attacks. The CVSS 3.0 vector is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, which aligns with a user-interaction-driven web redirection issue rather than direct system compromise.
- Vendor
- Flexerasoftware
- Product
- Flexnet Publisher
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2018-05-24
- Original CVE updated
- 2018-05-24
- Advisory published
- 2018-05-24
- Advisory updated
- 2018-05-24
Who should care
Administrators and security teams responsible for Flexera FlexNet Publisher / lmadmin deployments, especially Citrix License Server for Windows and Citrix License Server VPX. End-user support teams should also care because the main risk is user redirection and phishing.
Technical summary
The source corpus identifies CWE-601 (open redirect) in lmadmin, with affected FlexNet Publisher versions up to and including 11.14.1. The issue is network-reachable, requires no privileges, and depends on user interaction. The primary impact is limited confidentiality and integrity exposure through deceptive redirection, not direct availability impact.
Defensive priority
Medium. Prioritize remediation on any exposed or user-facing deployment because the flaw can be used for phishing and trust abuse, especially where license-server links are shared externally or embedded in workflows.
Recommended defensive actions
- Inventory any deployments of Flexera FlexNet Publisher lmadmin and Citrix License Server for Windows/VPX.
- Upgrade or migrate away from affected versions at or below FlexNet Publisher 11.14.1, following vendor remediation guidance in the cited Citrix/Flexera-related advisories.
- Restrict access to admin and license-management interfaces to trusted networks or authenticated users only.
- Review any links or redirects generated by the application and apply allowlist-based validation where possible.
- Educate users to verify destination URLs before following license-server or support links.
- Monitor web logs for unusual redirect patterns or repeated requests to redirect-style endpoints.
- If external exposure cannot be eliminated quickly, place the service behind VPN, reverse proxy controls, or other access restrictions.
Evidence notes
The NVD metadata for CVE-2017-5571 states an open redirect in lmadmin and maps the issue to CWE-601. It lists affected CPE criteria for flexerasoftware:flexnet_publisher versions up to and including 11.14.1 and provides the CVSS 3.0 vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The supplied reference set also includes Citrix, ICS-CERT, SecurityFocus, and Schneider Electric advisories, indicating multi-vendor awareness of the underlying FlexNet Publisher component.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5571 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5571
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5571 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5571
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://ics-cert.us-cert.gov/advisories/ICSA-18-144-01
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.citrix.com/article/CTX219885
[email protected] - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9134-vulnerabilities-within-schneider-electric-floating-license-manager
-
Source reference
Unverified legacy reference
URL: https://www.schneider-electric.com/en/download/document/SEVD-2018-137-01/
-
Source reference
Unverified legacy reference
URL: https://www.schneider-electric.com/en/download/document/SEVD-2018-144-01/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.