Back

HIGH

Protocol Downgrade in SIMPLE.ERP

Published Mar 24, 2025

Description

SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification.

This issue affect SIMPLE.ERP from 6.20 to 6.30. Only the 6.30 version received a patch 6.30@a03.9, which make it possible for an administrator to enforce encrypted communication. Versions 6.20 and 6.25 remain unpatched.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-PL
Published Mar 24, 2025
Updated Mar 24, 2025
Reserved Sep 13, 2024
CISA Vulnrichment
Updated Mar 24, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner CERT-PL
Published Mar 24, 2025
Updated Mar 24, 2025
Exploited since n/a
EUVD-2025-7986