CVE-2024-1149: Improper validation of update packages
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through 6.14.5; Inventory Agent: through 6.7.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1149?
CVE-2024-1149 is considered a high-severity vulnerability due to its potential for file manipulation.
How do I fix CVE-2024-1149?
To mitigate CVE-2024-1149, update the Snow Software Inventory Agent to a version above 6.14.5 or ensure that you are using a version below 6.7.2.
What systems are affected by CVE-2024-1149?
CVE-2024-1149 affects the Snow Software Inventory Agent on MacOS, Windows, and Linux systems.
What type of vulnerability is CVE-2024-1149?
CVE-2024-1149 is classified as an improper verification of cryptographic signature vulnerability.
Can CVE-2024-1149 allow unauthorized access?
Yes, CVE-2024-1149 may allow unauthorized file manipulation which could lead to unauthorized access.