Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0.
The vulnerability consists of the application accepting a request to downgrade the MS SQL communication protocol version initiated by the server side (or by an attacker impersonating the server). After forcing the downgrade, communication between the Wapro ERP Desktop client and the database server occurs without encryption. An attacker with access to the network segment can then eavesdrop on traffic (man-in-the-middle attack) and intercept or manipulate transmitted data.
An attacker can intercept confidential data transmitted between the application and the database server, including authentication credentials and business data, as well as make unauthorized modifications during transmission.
Wapro ERP Desktop should be updated to version 9.00.0 or newer. Additionally, network segmentation and restricting access to the segment where communication with the MS SQL server takes place are recommended to make man-in-the-middle attacks more difficult.
Wapro ERP Desktop in versions earlier than 9.00.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber