First published: Thu Feb 08 2024(Updated: )
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.
Credit: security@snowsoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Snowsoftware Snow Inventory Agent | <7.3.1 | |
opengroup Unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1150 is classified as a high severity vulnerability due to improper verification of cryptographic signatures, allowing file manipulation.
To mitigate CVE-2024-1150, update the Snow Software Inventory Agent to version 7.3.2 or higher.
CVE-2024-1150 affects the Snow Software Inventory Agent up to version 7.3.1 on Unix systems.
CVE-2024-1150 is an improper verification of cryptographic signature vulnerability.
Yes, if you are using Snow Software Inventory Agent version 7.3.1 or earlier on Unix, your system is at risk from CVE-2024-1150.