CRITICAL🇵🇱 Wersja polska

CVE-2024-4995

CVSS 9.1v4.0pub. 2024-12-18upd. 2026-04-15

Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0.

🤖 AI Analysis
How it works

The vulnerability consists of the application accepting a request to downgrade the MS SQL communication protocol version initiated by the server side (or by an attacker impersonating the server). After forcing the downgrade, communication between the Wapro ERP Desktop client and the database server occurs without encryption. An attacker with access to the network segment can then eavesdrop on traffic (man-in-the-middle attack) and intercept or manipulate transmitted data.

Impact

An attacker can intercept confidential data transmitted between the application and the database server, including authentication credentials and business data, as well as make unauthorized modifications during transmission.

Mitigation & patch

Wapro ERP Desktop should be updated to version 9.00.0 or newer. Additionally, network segmentation and restricting access to the segment where communication with the MS SQL server takes place are recommended to make man-in-the-middle attacks more difficult.

Who is affected

Wapro ERP Desktop in versions earlier than 9.00.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References