Comarch ERP XL Vulnerable to MS SQL Protocol Downgrade Attack
CVE-2023-4537

7.4HIGH

Key Information:

Vendor

Comarch

Status
Vendor
CVE Published:
15 February 2024

What is CVE-2023-4537?

The vulnerability allows an attacker to exploit a weakness in the MS SQL protocol used by Comarch ERP XL, specifically through a downgrade request that is initiated from the server side. This can lead to configurations that permit unencrypted communication channels. Consequently, sensitive information transmitted over these channels is susceptible to interception and modification by unauthorized entities. This issue is present in multiple versions of Comarch ERP XL, making it critical for users to promptly address this vulnerability to protect their data integrity and security.

Affected Version(s)

ERP XL 2020.2.2 <= 2023.2

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dr inĹĽ. Marcin Ochab
.