HIGH🇬🇧 English

CVE-2024-1150

CVSS 7.8v3.1pub. 2024-02-08upd. 2024-11-21

Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Opengroup Unix

    OS
    Opengroup
    wszystkie wersje
  • Snowsoftware Snow Inventory Agent

    APP
    Snowsoftware
    < 7.3.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2013-0625CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Adobe ColdFusion — pominięcie uwierzytelnienia bez hasła (Auth Bypass)

CVE-2011-2462CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w komponencie U3D Adobe Reader i Acrobat — aktywnie exploitowany

CVE-2020-6294CRITICAL9.1PL ✓ten sam produkt

SAP BusinessObjects BI Platform – brak uwierzytelnienia w komponencie Xvfb (Unix)

CVE-2019-9895CRITICAL9.8PL ✓ten sam produkt

Buffer overflow w PuTTY przed wersją 0.71 na systemach Unix

CVE-2022-30333HIGH7.5⚠ KEVten sam produkt

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka...