Snowsoftware develops a suite of software-asset and license-management tools, including inventory agents, command-and-control platforms, and access proxies, that operate across organizational IT infrastructure and handle sensitive deployment and authentication data. Vulnerabilities affecting the vendor show a moderate tendency toward serious outcomes, with a meaningful share reaching critical severity and a corresponding tendency toward confirmed in-the-wild exploitation and public exploit availability. The recurring weaknesses concentrate on cryptographic-signature verification, authentication bypass via spoofing, deserialization of untrusted data, and input validation across these management products, reflecting the trust boundaries and data-handling demands of tools that broker access and deployment decisions. Defenders should prioritize patching these vendor's management tier and restrict network exposure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Snowsoftware over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2022-0883HIGH SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched. | May 18, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-4106HIGH A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0 | Feb 16, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-27579HIGH Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed and in use across an IT environment. A privilege-escalation | Feb 23, 2021 | 7.8 | 24 | NO | NO |
CVE-2023-3864HIGH Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to i | Aug 11, 2023 | 7.2 | 22 | NO | NO |
CVE-2021-41562MEDIUM A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue affects: Snow Snow Agent for Windows version 5.0.0 to 6.7.1 | Nov 3, 2021 | 6.1 | 21 | NO | NO |
CVE-2024-1149MEDIUM Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on | Feb 8, 2024 | 5.5 | 18 | NO | NO |
CVE-2023-2679MEDIUM Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data. | May 17, 2023 | 4.3 | 17 | NO | NO |
CVE-2024-1150MEDIUM Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inv | Feb 8, 2024 | 5.5 | 15 | NO | NO |
CVE-2023-7169MEDIUM Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Cus | Feb 8, 2024 | 5.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Snowsoftware.
Media articles that mention a CVE ID that affects a product developed by Snowsoftware — matched by CVE ID, not by vendor name.