MidnightBSD

Advisories for snowsoftware

CVE-2021-27579 MEDIUM

Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed and in use across an IT environment. A privilege-escalation vulnerability exists if CPUID is enabled, and thus it should be disabled via configuration settings.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
snowsoftware snow_inventory_agent *
CVE-2021-4106 HIGH

A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9
security@snowsoftware.com 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-691,NVD-CWE-Other,

Products Affected

Vendor Product Version
snowsoftware snow_inventory_java_scanner 1.0
CVE-2021-41562 LOW

A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue affects: Snow Snow Agent for Windows version 5.0.0 to 6.7.1 on Windows.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H 1.8 4.2
security@snowsoftware.com 6.1 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H 1.8 4.2

CVSS 2.0

Severity: LOW

Problem Type: CWE-64,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
snowsoftware snow_inventory_agent *
CVE-2021-44228 HIGH

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 3.9 6.0

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,CWE-400,CWE-502,CWE-917,

Products Affected

Vendor Product Version
cisco unified_customer_voice_portal 12.0
siemens nx *
cisco evolved_programmable_network_manager 5.1
cisco crosswork_platform_infrastructure *
siemens mindsphere *
cisco nexus_insights *
cisco paging_server 8.4(1)
cisco ucs_central_software 2.0(1f)
cisco unified_customer_voice_portal 12.5(1)
cisco video_surveillance_operations_manager *
cisco unified_sip_proxy 010.000(000)
cisco unified_sip_proxy 010.002(000)
cisco firepower_threat_defense 7.0.0
cisco cloudcenter_suite 5.5.0
cisco unified_contact_center_enterprise *
siemens siveillance_vantage *
cisco network_dashboard_fabric_controller 11.2(1)
cisco webex_meetings_server 4.0
cisco unified_communications_manager_im_&_presence_service 11.5(1.22900.6)
siemens siveillance_control_pro *
siemens siveillance_viewpoint *
cisco data_center_network_manager *
siemens solid_edge_cam_pro *
cisco identity_services_engine *
siemens operation_scheduler *
cisco common_services_platform_collector 002.009(000.002)
cisco emergency_responder *
cisco paging_server 12.5(2)
siemens siveillance_identity 1.6
cisco virtual_topology_system *
cisco identity_services_engine 002.006(000.156)
siemens siguard_dsa 4.3
cisco ucs_central *
apache log4j *
netapp cloud_insights -
netapp ontap_tools -
siemens sipass_integrated 2.80
cisco cloudcenter_cost_optimizer *
siemens siguard_dsa *
siemens energyip 8.7
cisco unified_contact_center_express 12.6(2)
debian debian_linux 9.0
cisco packaged_contact_center_enterprise *
cisco unified_intelligence_center *
cisco prime_service_catalog *
cisco ucs_central_software 2.0(1h)
netapp oncommand_insight -
cisco webex_meetings_server *
cisco ucs_central_software 2.0(1c)
cisco smart_phy *
cisco paging_server 8.3(1)
cisco firepower_threat_defense 6.3.0
cisco fxos 7.1.0
cisco virtual_topology_system 2.6.6
cisco unified_workforce_optimization 11.5(1)
cisco paging_server 9.0(1)
cisco network_dashboard_fabric_controller 11.1(1)
cisco unified_communications_manager *
intel datacenter_manager *
cisco broadworks -
cisco unified_contact_center_management_portal 12.6(1)
cisco common_services_platform_collector 002.009(001.001)
cisco common_services_platform_collector 002.009(001.002)
cisco identity_services_engine 002.007(000.356)
intel data_center_manager *
cisco common_services_platform_collector *
cisco cloud_connect *
cisco unified_contact_center_express 12.6(1)
cisco unified_communications_manager_im_and_presence_service *
cisco cloudcenter_suite 5.4.1
siemens energy_engage 3.1
cisco unified_communications_manager 11.5(1.22900.28)
cisco intersight_virtual_appliance *
cisco unified_sip_proxy *
cisco intersight_virtual_appliance 1.0.9-343
cisco unified_communications_manager 11.5(1.17900.52)
cisco crosswork_zero_touch_provisioning 3.0.0
cisco connected_analytics_for_network_deployment 007.003.001.001
siemens desigo_cc_advanced_reports 5.1
cisco enterprise_chat_and_email *
cisco finesse 12.6(1)
cisco crosswork_network_controller *
cisco wan_automation_engine 7.2.1
siemens head-end_system_universal_device_integration_system *
cisco network_dashboard_fabric_controller 11.5(3)
cisco wan_automation_engine 7.2.2
intel system_debugger -
cisco network_services_orchestrator -
cisco paging_server *
cisco common_services_platform_collector 002.010(000.000)
cisco cloudcenter *
sonicwall email_security *
cisco paging_server 14.0(1)
cisco cloudcenter_suite 5.5.1
bentley synchro *
siemens 6bk1602-0aa32-0tp0_firmware *
cisco fxos 6.3.0
cisco advanced_malware_protection_virtual_private_cloud_appliance *
fedoraproject fedora 35
siemens captial *
bentley synchro_4d *
cisco cloudcenter_suite 5.3.0
cisco video_surveillance_manager 7.14(1.26)
cisco video_surveillance_manager 7.14(4.018)
intel sensor_solution_firmware_development_kit -
cisco fxos 6.2.3
cisco crosswork_network_automation 2.0.0
cisco cyber_vision 4.0.2
siemens sentron_powermanager 4.2
cisco workload_optimization_manager *
cisco dna_spaces -
cisco unified_contact_center_express 12.5(1)
fedoraproject fedora 34
siemens mendix *
cisco sd-wan_vmanage 20.3
siemens desigo_cc_info_center 5.0
cisco unified_contact_center_enterprise 12.6(1)
siemens solid_edge_harness_design 2020
siemens sentron_powermanager 4.1
siemens spectrum_power_4 4.70
cisco firepower_threat_defense 6.7.0
siemens desigo_cc_advanced_reports 4.2
cisco cloudcenter_suite 5.5(1)
cisco prime_service_catalog 12.1
intel secure_device_onboard -
cisco ucs_central_software 2.0(1a)
cisco unified_customer_voice_portal 12.0(1)
cisco unified_intelligence_center 12.6(1)
cisco ucs_director *
siemens energyip 8.5
cisco common_services_platform_collector 002.009(000.001)
debian debian_linux 10.0
cisco unified_communications_manager 11.5(1)
siemens xpedition_package_integrator -
cisco unified_communications_manager 11.5(1.21900.40)
cisco firepower_threat_defense 6.5.0
siemens vesys 2021.1
cisco connected_analytics_for_network_deployment 006.004.000.003
cisco cyber_vision_sensor_management_extension *
cisco unified_contact_center_enterprise 12.6(2)
siemens desigo_cc_advanced_reports 4.0
cisco network_dashboard_fabric_controller 11.5(2)
siemens xpedition_enterprise -
cisco network_dashboard_fabric_controller 11.4(1)
intel computer_vision_annotation_tool -
cisco ucs_central_software 2.0(1l)
cisco connected_analytics_for_network_deployment 008.000.000.000.004
cisco unified_contact_center_enterprise 12.5(1)
siemens vesys 2019.1
cisco evolved_programmable_network_manager 3.0
cisco unified_intelligence_center 12.6(2)
cisco cloudcenter_workload_manager *
apache log4j 2.0
cisco cx_cloud_agent 001.012
siemens industrial_edge_management *
cisco smart_phy 3.1.5
siemens energyip_prepay 3.7
intel system_studio -
cisco crosswork_optimization_engine 3.0.0
cisco automated_subsea_tuning *
cisco virtualized_voice_browser *
cisco connected_analytics_for_network_deployment 006.005.000.
cisco evolved_programmable_network_manager 4.0
cisco smart_phy 3.2.1
cisco wan_automation_engine *
siemens energyip_prepay 3.8
cisco sd-wan_vmanage 20.7
cisco unified_computing_system 006.008(001.000)
siemens siguard_dsa 4.2
cisco sd-wan_vmanage 20.4
cisco identity_services_engine 2.4.0
cisco evolved_programmable_network_manager 5.0
siemens 6bk1602-0aa12-0tp0_firmware *
cisco broadworks *
siemens vesys 2020.1
cisco emergency_responder 11.5
siemens solid_edge_harness_design *
cisco crosswork_data_gateway 3.0.0
cisco ucs_central_software 2.0(1e)
siemens sipass_integrated 2.85
netapp brocade_san_navigator -
cisco enterprise_chat_and_email 12.6(1)
cisco fxos 6.6.0
cisco data_center_network_manager 11.3(1)
siemens spectrum_power_7 2.30
cisco unified_customer_voice_portal 11.6
intel audio_development_kit -
cisco firepower_threat_defense 6.4.0
cisco identity_services_engine 002.004(000.914)
cisco smart_phy 3.1.4
cisco connected_analytics_for_network_deployment 007.003.003
cisco mobility_services_engine -
cisco sd-wan_vmanage 20.8
siemens 6bk1602-0aa22-0tp0_firmware *
cisco crosswork_zero_touch_provisioning *
cisco finesse 12.5(1)
cisco ucs_central_software 2.0(1k)
cisco paging_server 8.5(1)
netapp cloud_secure_agent -
cisco network_assurance_engine *
cisco identity_services_engine 003.002(000.116)
cisco cloudcenter_suite 5.3(0)
cisco fxos 7.0.0
cisco paging_server 9.0(2)
siemens 6bk1602-0aa42-0tp0_firmware *
cisco firepower_threat_defense 6.2.3
cisco unified_communications_manager 11.5(1)su3
cisco smart_phy 3.1.3
cisco crosswork_network_automation 3.0.0
cisco ucs_central_software 2.0(1g)
netapp cloud_manager -
cisco network_insights_for_data_center 6.0(2.1914)
apple xcode *
cisco iot_operations_dashboard -
cisco integrated_management_controller_supervisor 002.003(002.000)
cisco unified_customer_voice_portal 11.6(1)
cisco network_services_orchestrator *
siemens desigo_cc_advanced_reports 5.0
cisco unified_workforce_optimization *
intel genomics_kernel_library -
siemens siguard_dsa 4.4
cisco unified_contact_center_express *
siemens capital 2019.1
cisco cloudcenter_suite 5.5(0)
cisco crosswork_network_automation -
cisco unity_connection 11.5(1.10000.6)
cisco ucs_central_software 2.0(1d)
siemens vesys *
cisco cloudcenter_suite 5.4(1)
cisco smart_phy 3.1.2
cisco fog_director -
cisco webex_meetings_server 3.0
snowsoftware snow_commander *
cisco virtualized_infrastructure_manager *
cisco unified_contact_center_enterprise 12.0(1)
cisco cloudcenter_suite_admin *
cisco firepower_threat_defense 7.1.0
netapp active_iq_unified_manager -
cisco connected_analytics_for_network_deployment 007.002.000
cisco connected_analytics_for_network_deployment 007.003.000
cisco contact_center_management_portal *
cisco enterprise_chat_and_email 12.0(1)
cisco network_dashboard_fabric_controller 11.3(1)
cisco firepower_threat_defense 6.6.0
cisco contact_center_domain_manager *
cisco identity_services_engine 003.001(000.518)
cisco unified_customer_voice_portal 12.5
cisco crosswork_network_controller 3.0.0
siemens 6bk1602-0aa52-0tp0_firmware *
cisco integrated_management_controller_supervisor *
cisco packaged_contact_center_enterprise 11.6(1)
cisco sd-wan_vmanage *
cisco crosswork_optimization_engine *
cisco fxos 6.5.0
cisco wan_automation_engine 7.6
cisco network_dashboard_fabric_controller 11.0(1)
cisco dna_spaces_connector -
siemens desigo_cc_info_center 5.1
cisco crosswork_platform_infrastructure 4.1.0
cisco smart_phy 21.3
cisco integrated_management_controller_supervisor 2.3.2.0
cisco optical_network_controller 1.1
cisco ucs_central_software 2.0(1b)
siemens energyip_prepay *
cisco customer_experience_cloud_agent *
cisco sd-wan_vmanage 20.6
cisco unified_sip_proxy 010.002(001)
cisco common_services_platform_collector 002.009(000.000)
cisco paging_server 9.1(1)
siemens captial 2019.1
siemens capital *
cisco cloudcenter_suite 4.10.0.15
siemens opcenter_intelligence *
cisco fxos 6.7.0
cisco dna_center *
siemens comos *
cisco connected_analytics_for_network_deployment 007.001.000
cisco network_dashboard_fabric_controller 11.5(1)
cisco wan_automation_engine 7.4
percussion rhythmyx *
cisco optical_network_controller *
cisco unified_contact_center_enterprise 11.6(2)
cisco connected_analytics_for_network_deployment 007.000.001
cisco wan_automation_engine 7.5
cisco business_process_automation *
cisco common_services_platform_collector 002.009(001.000)
siemens desigo_cc_advanced_reports 4.1
cisco unified_communications_manager 11.5(1.18119.2)
snowsoftware vm_access_proxy *
siemens e-car_operation_center *
cisco video_surveillance_manager 7.14(3.025)
cisco evolved_programmable_network_manager *
cisco unified_communications_manager_im_&_presence_service 11.5(1)
siemens industrial_edge_management_hub *
siemens desigo_cc_advanced_reports 3.0
cisco dna_center 2.2.2.8
cisco unity_connection *
cisco emergency_responder 11.5(4.66000.14)
cisco wan_automation_engine 7.3
cisco unified_customer_voice_portal 12.6(1)
cisco ucs_central_software 2.0
netapp solidfire_enterprise_sds -
cisco connected_analytics_for_network_deployment 008.000.000
siemens sppa-t3000_ses3000_firmware *
cisco crosswork_network_automation 4.1.0
cisco automated_subsea_tuning 02.01.00
cisco connected_analytics_for_network_deployment 006.005.000.000
cisco unified_communications_manager_im_and_presence_service 11.5(1)
cisco sd-wan_vmanage 20.5
siemens siveillance_identity 1.5
cisco connected_mobile_experiences -
cisco sd-wan_vmanage 20.6.1
siemens spectrum_power_7 *
cisco finesse *
cisco network_assurance_engine 6.0(2.1912)
siemens energyip 8.6
siemens gma-manager *
netapp snapcenter -
cisco cloudcenter_suite 4.10(0.15)
cisco unified_sip_proxy 010.000(001)
cisco wan_automation_engine 7.2.3
netapp solidfire_&_hci_storage_node -
siemens energyip 9.0
cisco identity_services_engine 003.000(000.458)
siemens spectrum_power_4 *
cisco wan_automation_engine 7.1.3
intel oneapi_sample_browser -
cisco fxos 6.4.0
cisco nexus_dashboard *
cisco connected_analytics_for_network_deployment 7.3
siemens teamcenter *
cisco evolved_programmable_network_manager 3.1
cisco video_surveillance_manager 7.14(2.26)
siemens siveillance_command *
debian debian_linux 11.0
cisco crosswork_data_gateway *
cisco unified_customer_voice_portal *
cisco cyber_vision_sensor_management_extension 4.0.2
cisco crosswork_network_automation 4.1.1
cisco emergency_responder 11.5(4.65000.14)
cisco enterprise_chat_and_email 12.5(1)
cisco unified_communications_manager 11.5(1.18900.97)
cisco unity_connection 11.5
siemens logo!_soft_comfort *
cisco evolved_programmable_network_manager 4.1
siemens navigator *
cisco dna_spaces:_connector *
CVE-2022-0883 MEDIUM

SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9
security@snowsoftware.com 7.3 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H 1.3 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-428,CWE-428,

Products Affected

Vendor Product Version
snowsoftware snow_license_manager *
CVE-2023-2679

Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security@snowsoftware.com 4.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N 2.3 1.4

Products Affected

Vendor Product Version
snowsoftware snow_license_manager *
CVE-2023-3864

Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9
security@snowsoftware.com 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 1.2 5.9

Products Affected

Vendor Product Version
snowsoftware snow_license_manager *
CVE-2023-3937

Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security@snowsoftware.com 4.8 MEDIUM CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N 1.7 2.7
nvd@nist.gov 4.8 MEDIUM CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N 1.7 2.7

Products Affected

Vendor Product Version
snowsoftware snow_license_manager *
CVE-2023-7169

Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Customers advised to upgrade to version 7.0

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security@snowsoftware.com 6.0 MEDIUM CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N 0.8 5.2

Products Affected

Vendor Product Version
snowsoftware snow_inventory_agent *
CVE-2024-1149

Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through 6.14.5; Inventory Agent: through 6.7.2.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security@snowsoftware.com 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

Products Affected

Vendor Product Version
snowsoftware snow_inventory_agent *
snowsoftware snow_inventory_agent 6.12.0
CVE-2024-1150

Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security@snowsoftware.com 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

Products Affected

Vendor Product Version
snowsoftware snow_inventory_agent *