CVE-2023-7169: Impersonate vendor signed Powershell scripts
Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Customers advised to upgrade to version 7.0
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7169?
CVE-2023-7169 has been classified as a high-severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2023-7169?
To fix CVE-2023-7169, customers should upgrade the Snow Inventory Agent to version 7.0 or later.
What types of systems are affected by CVE-2023-7169?
CVE-2023-7169 affects the Snow Inventory Agent running on Windows, specifically versions through 6.14.5.
What is the nature of the vulnerability in CVE-2023-7169?
CVE-2023-7169 is an authentication bypass vulnerability that can be exploited through signature spoofing.
Is there a specific version that resolves CVE-2023-7169?
Yes, upgrading to version 7.0 of the Snow Inventory Agent resolves the vulnerabilities associated with CVE-2023-7169.