CVE Database
/

CVE-2024-8773

Back to search

CVE-2024-8773

Published: Mar 24, 2025

Modified: Mar 24, 2025

PUBLISHED

Description

SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affect SIMPLE.ERP from 6.20 to 6.30. Only the 6.30 version received a patch [email protected], which make it possible for an administrator to enforce encrypted communication. Versions 6.20 and 6.25 remain unpatched.

VendorProductVersions

Simple SA

SIMPLE.ERP

affected
6.20 - < [email protected]

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now