CVE Vulnerabilities

CVE-2024-1149

Improper Verification of Cryptographic Signature

Published: Feb 08, 2024 | Modified: Feb 15, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through 6.14.5; Inventory Agent: through 6.7.2.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Snow_inventory_agent Snowsoftware * 6.7.2 (excluding)
Snow_inventory_agent Snowsoftware 6.14.0 (including) 6.14.5 (excluding)
Snow_inventory_agent Snowsoftware 6.12.0 (including) 6.12.0 (including)

References