VulnerabilityModified
CVE-2024-1150
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.
MEDIUM 5.5EPSS 0.12%
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- snowsoftware/snow inventory agent
- Source
- security@snowsoftware.com
References
- https://community.snowsoftware.com/s/feed/0D5Td000004YtMcKAKVendor Advisory
- https://community.snowsoftware.com/s/feed/0D5Td000004YtMcKAKVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.