CVE-2024-1150: Improper validation of update packages
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1150?
CVE-2024-1150 is classified as a high severity vulnerability due to improper verification of cryptographic signatures, allowing file manipulation.
How do I fix CVE-2024-1150?
To mitigate CVE-2024-1150, update the Snow Software Inventory Agent to version 7.3.2 or higher.
What software is affected by CVE-2024-1150?
CVE-2024-1150 affects the Snow Software Inventory Agent up to version 7.3.1 on Unix systems.
What type of vulnerability is CVE-2024-1150?
CVE-2024-1150 is an improper verification of cryptographic signature vulnerability.
Can CVE-2024-1150 affect my system?
Yes, if you are using Snow Software Inventory Agent version 7.3.1 or earlier on Unix, your system is at risk from CVE-2024-1150.