Snow Software
First CVE: Nov 3, 2021Active for: 5 years
10
CVEs Published
More CVEs Published than 27% of tracked CNAs
2.5
Avg CVEs / Year
More Avg CVEs / Year than 16% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 19% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Snow Software over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2021
4 years ago
Most Recent CVE
May 14, 2024
801 days ago
Top CVEs
All CVEs published by Snow Software as a CNA, regardless of affected vendor or product.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0883HIGH SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched. | May 18, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-4106HIGH A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0 | Feb 16, 2022 | 7.8 | 25 | NO | NO |
CVE-2024-4129HIGH Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authen | May 14, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-3864HIGH Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to i | Aug 11, 2023 | 7.2 | 22 | NO | NO |
CVE-2021-41562MEDIUM A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue affects: Snow Snow Agent for Windows version 5.0.0 to 6.7.1 | Nov 3, 2021 | 6.1 | 21 | NO | NO |
CVE-2024-1149MEDIUM Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on | Feb 8, 2024 | 5.5 | 18 | NO | NO |
CVE-2023-2679MEDIUM Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data. | May 17, 2023 | 4.3 | 17 | NO | NO |
CVE-2024-1150MEDIUM Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inv | Feb 8, 2024 | 5.5 | 15 | NO | NO |
CVE-2023-7169MEDIUM Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Cus | Feb 8, 2024 | 5.5 | 15 | NO | NO |
CVE-2023-3937MEDIUM Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high pr | Aug 11, 2023 | 4.8 | 15 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA10 CVEs
60%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (60.0%)
Network4 (40.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low8 (80.0%)
High2 (20.0%)
None0 (0.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Snow Software as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Snow Software as a CNA — matched by CVE ID, not by organization name.