Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Snowsoftware

First CVE: Feb 23, 2021Active for: 5 yearsTotal CVEs: 11
58.5
VTI Score
TOP TARGET

Snowsoftware develops a suite of software-asset and license-management tools, including inventory agents, command-and-control platforms, and access proxies, that operate across organizational IT infrastructure and handle sensitive deployment and authentication data. Vulnerabilities affecting the vendor show a moderate tendency toward serious outcomes, with a meaningful share reaching critical severity and a corresponding tendency toward confirmed in-the-wild exploitation and public exploit availability. The recurring weaknesses concentrate on cryptographic-signature verification, authentication bypass via spoofing, deserialization of untrusted data, and input validation across these management products, reflecting the trust boundaries and data-handling demands of tools that broker access and deployment decisions. Defenders should prioritize patching these vendor's management tier and restrict network exposure; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
9.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Snowsoftware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2021
5 years ago
Most Recent CVE
Feb 8, 2024
897 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-44228CRITICAL
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
CVE-2022-0883HIGH
SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.
May 18, 20227.825NONO
CVE-2021-4106HIGH
A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0
Feb 16, 20227.825NONO
CVE-2021-27579HIGH
Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed and in use across an IT environment. A privilege-escalation
Feb 23, 20217.824NONO
CVE-2023-3864HIGH
Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to i
Aug 11, 20237.222NONO
CVE-2021-41562MEDIUM
A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue affects: Snow Snow Agent for Windows version 5.0.0 to 6.7.1
Nov 3, 20216.121NONO
CVE-2024-1149MEDIUM
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on
Feb 8, 20245.518NONO
CVE-2023-2679MEDIUM
Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data.
May 17, 20234.317NONO
CVE-2024-1150MEDIUM
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inv
Feb 8, 20245.515NONO
CVE-2023-7169MEDIUM
Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Cus
Feb 8, 20245.515NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
55%
36%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (63.6%)
Network4 (36.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low8 (72.7%)
High2 (18.2%)
None1 (9.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
1 CVE
9.1% of CVEs· 100th percentile
Metasploit
1 CVE
9.1% of CVEs· 98th percentile
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Snowsoftware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Snowsoftware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Snowsoftware's Products

View all 3 CNAs →

Top CWEs