NONE · 0

CVE-2024-8773

SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue a...

Vulnerability Description

SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affect SIMPLE.ERP from 6.20 to 6.30. Only the 6.30 version received a patch [email protected], which make it possible for an administrator to enforce encrypted communication. Versions 6.20 and 6.25 remain unpatched.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-8773?

CVE-2024-8773 is a documented vulnerability. SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue a...

How severe is CVE-2024-8773?

CVSS scoring is not yet available for CVE-2024-8773. Check NVD for updates.

Is there a patch for CVE-2024-8773?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.