s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-4995

📛 CVE Title

Protocol Downgrade in Wapro ERP Desktop

Description

Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0.

Overview

State
PUBLISHED
Assigner (CNA)
CERT-PL
CVSS severity
CRITICAL
CVSS score
CVSS 9.1 / 10 9.1 9.1 / 10
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/R:U/V:C/RE:M/U:Amber
Effective score
9.1 / 10 CRITICAL source: CNA overview
CWE(s)
CWE-757
Reserved
2024-05-16
Published
2024-12-18 12:36 UTC
Last updated
2025-10-07 15:20 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4995.json
Linked Threat
CVE-2024-4995 — Protocol Downgrade in Wapro ERP Desktop

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-44562
Assigner
CERT-PL
Published
Dec 18, 2024, 11:36:47 AM
Updated
Oct 7, 2025, 1:20:30 PM
EUVD base score (CVSS 4.0)
9.1 / 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/R:U/V:C/RE:M/U:Amber
EUVD-reported EPSS
0.2600
Vendors
Asseco Business Solutions S.A.
Products
Wapro ERP Desktop (0 <9.00.0)
Aliases
GHSA-5922-vxrc-h3gf

ENISA description: Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0.

EUVD references (3)

Affected products (1)

VendorProductVersionsPlatforms
Asseco Business Solutions S.A. Wapro ERP Desktop 0 (affected)

Vendor references (3)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (17)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:arcticwolf.com

    Threat Summary On June 9, 2026, Microsoft released its regular Patch Tuesday security update, fixing 206 vulnerabilities (with 39 rated Critical) affecting a broad spectrum of Microsoft products including Windows kernel, Hyper-V, Remote Desktop Client, Kerberos, DHCP, BitLocker, HTTP.sys, Exchange Server, and Office. This is the largest number of vulnerabilities ever disclosed in a single ...

    2026-08-05 15:27 UTC
  • web:msrc.microsoft.com

    Security Update Guide - Microsoft Security Response Center

    2026-08-05 15:27 UTC
  • web:www.cisa.gov

    Updated October 29, 2025: CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE -2025-59287

    2026-08-05 15:27 UTC
  • web:www.crowdstrike.com

    Microsoft patches 206 vulnerabilities in June 2026 Patch Tuesday, including three publicly disclosed zero-days.

    2026-08-05 15:27 UTC
  • web:www.nist.gov

    NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.

    2026-08-05 15:27 UTC
  • web:www.rapid7.com

    Microsoft has published 172 new vulnerabilities, including six zero-day vulnerabilities. Windows 10 moves past the end of support, sort of. Critical RCE in Windows Server Update Service.

    2026-08-05 15:27 UTC
  • web:zecurit.com

    Get the complete breakdown of Microsoft's July 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

    2026-08-05 15:27 UTC
  • web:www.securityweek.com

    Microsoft has announced mitigations for CVE -2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.

    2026-05-22 10:39 UTC
  • web:www.maketecheasier.com

    Check out the latest Windows 11 and Windows 10 update problems and their solutions, as recommended by Microsoft experts.

    2026-05-22 10:39 UTC
  • web:www.ultimatewindowssecurity.com

    Welcome to my April 2026 Patch Tuesday newsletter. This month is huge with 167 updates released today and another 344 released since our newsletter last month for a staggering 512 updates. I haven't seen a list of updates this long in years. The good news is that we only have two zero-days to talk about. So, let's get to it.

    2026-05-22 10:39 UTC
  • web:www.oracle.com

    Oracle Critical Patch Update Advisory - April 2025 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...

    2026-05-22 10:39 UTC
  • web:cyberpress.org

    A newly published proof-of-concept tool called BitUnlocker exposes a dangerous downgrade attack that can bypass Microsoft's BitLocker full-disk encryption on fully patched Windows 11 machines, granting complete access to encrypted drives in under five minutes. The attack exploits CVE -2025-48804, a vulnerability in Windows BitLocker that allows an attacker to mix untrusted data with trusted ...

    2026-05-22 10:39 UTC
  • web:cybersecuritynews.com

    No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.

    2026-05-22 10:39 UTC
  • web:www.pcworld.com

    Windows 11's Secure Boot fix update finally rolls out to more PCs Important security certificates for Windows 11 will soon expire for many users.

    2026-05-22 10:39 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-22 10:39 UTC
  • web:robertsspaceindustries.com

    Hi Everyone! Time again for another Hotfix Central thread to keep you all up to date on things going on outside of the normal patch cycle in SC Alpha 4.8 LIVE! This will be a living document of...

    2026-05-22 10:39 UTC
  • web:www.windowslatest.com

    Windows 11 April 2026 update adds Narrator Copilot support, faster Settings, File Explorer fixes, and key security improvements.

    2026-05-22 10:39 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2024-4995.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "HIGH",
              "baseScore": 9.8,
              "baseSeverity": "CRITICAL",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-4995",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-12-18T14:49:13.283552Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-922",
                "description": "CWE-922 Insecure Storage of Sensitive Information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-07T13:20:30.088Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Wapro ERP Desktop",
          "vendor": "Asseco Business Solutions S.A.",
          "versions": [
            {
              "lessThan": "9.00.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "datePublic": "2024-12-18T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Wapro ERP Desktop <span style=\"background-color: rgb(252, 252, 252);\">is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification.&nbsp;</span><p>This issue affects Wapro ERP Desktop versions before 9.00.0.</p>"
            }
          ],
          "value": "Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification.\u00a0This issue affects Wapro ERP Desktop versions before 9.00.0."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-569",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-569 Collect Data as Provided by Users"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "USER",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "privilegesRequired": "NONE",
            "providerUrgency": "AMBER",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "CONCENTRATED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/R:U/V:C/RE:M/U:Amber",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "MODERATE"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-757",
              "description": "CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-03T08:55:28.841Z",
        "orgId": "4bb8329e-dd38-46c1-aafb-9bf32bcb93c6",
        "shortName": "CERT-PL"
      },
      "references": [
        {
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://cert.pl/en/posts/2024/12/CVE-2024-4995/"
        },
        {
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://cert.pl/posts/2024/12/CVE-2024-4995/"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://wapro.pl/"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Protocol Downgrade in Wapro ERP Desktop",
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "4bb8329e-dd38-46c1-aafb-9bf32bcb93c6",
    "assignerShortName": "CERT-PL",
    "cveId": "CVE-2024-4995",
    "datePublished": "2024-12-18T11:36:47.588Z",
    "dateReserved": "2024-05-16T10:39:00.184Z",
    "dateUpdated": "2025-10-07T13:20:30.088Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}