HIGH🇵🇱 Wersja polska

CVE-2024-1150

CVSS 7.8v3.1pub. 2024-02-08upd. 2024-11-21

Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Opengroup Unix

    OS
    Opengroup
    all versions
  • Snowsoftware Snow Inventory Agent

    APP
    Snowsoftware
    < 7.3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2013-0625CRITICAL9.8⚠ KEVPL ✓same product

Adobe ColdFusion — pominięcie uwierzytelnienia bez hasła (Auth Bypass)

CVE-2011-2462CRITICAL9.8⚠ KEVPL ✓same product

RCE w komponencie U3D Adobe Reader i Acrobat — aktywnie exploitowany

CVE-2020-6294CRITICAL9.1PL ✓same product

SAP BusinessObjects BI Platform – brak uwierzytelnienia w komponencie Xvfb (Unix)

CVE-2019-9895CRITICAL9.8PL ✓same product

Buffer overflow w PuTTY przed wersją 0.71 na systemach Unix

CVE-2022-30333HIGH7.5⚠ KEVsame product

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka...