Back to Database
Status published
High
CVE-2024-1150
Improper validation of update packages
Vulnerability Description
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1150
Credits & Attribution
No credits recorded in the NVD database.
More from Snow Software
View All →CVE-2024-1149
Improper validation of update packages
High
7.8
CVE-2023-7169
Impersonate vendor signed Powershell scripts
Medium
6
CVE-2023-3937
Cross site scripting vulnerabilities in Snow License Manager
Medium
4.8
CVE-2023-3864
SQL injection vulnerability in Snow License Manager
High
7.2
CVE-2023-2679
Data leakage in Adobe connector for SPE edition of SLM
Medium
4.1
Affected Vendor
Snow Software
View all reports →Affected Software
Inventory Agent
Vulnerable Versions:
0
Timeline
Official Publish:
February 8th, 2024
Last Modified:
August 1st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H