PT-2024-33792 · Microsoft · Mssql

Published

2024-12-18

·

Updated

2025-10-03

·

CVE-2024-4995

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Wapro ERP Desktop versions prior to 9.00.0
Description: The issue affects Wapro ERP Desktop, where it is vulnerable to MS SQL protocol downgrade requests from the server side. This could lead to unencrypted communication, making it vulnerable to data interception and modification.
Recommendations: For versions prior to 9.00.0, update to version 9.00.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of MS SQL protocol to minimize the risk of exploitation.

Fix

Missing Encryption of Sensitive Data

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-4995

Affected Products

Mssql