First published: Thu Feb 08 2024(Updated: )
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through 6.14.5; Inventory Agent: through 6.7.2.
Credit: security@snowsoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Snowsoftware Snow Inventory Agent | <6.7.2 | |
Snowsoftware Snow Inventory Agent | >=6.14.0<6.14.5 | |
Snowsoftware Snow Inventory Agent | =6.12.0 | |
Any of | ||
Apple macOS | ||
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1149 is considered a high-severity vulnerability due to its potential for file manipulation.
To mitigate CVE-2024-1149, update the Snow Software Inventory Agent to a version above 6.14.5 or ensure that you are using a version below 6.7.2.
CVE-2024-1149 affects the Snow Software Inventory Agent on MacOS, Windows, and Linux systems.
CVE-2024-1149 is classified as an improper verification of cryptographic signature vulnerability.
Yes, CVE-2024-1149 may allow unauthorized file manipulation which could lead to unauthorized access.