Attention 3CX Version 20 (Debian 12 Bookworm) users.

A critical vulnerability has been discovered in OpenSSH ("regreSSHion" - CVE-2024-6387). Although nothing to do with 3CX, we’re pleased to have been able to demonstrate our ability to release this update within 24 hours. To protect your 3CX System, please update immediately.

How to Update

How to Update your 3CX

  1. Log in to your 3CX Admin Console.
  2. Go to System > Updates.
  3. Enable “Automatic Update 3CX” if you disabled it and set a daily time for updates.
  4. Wait for the system to automatically download and install the security updates.

Hosted by 3CX

The update has already been installed for you. No action is required on your part.

Debian 10 Buster (Version 18)

The “regreSSHion” vulnerability does not currently affect Debian 10 systems. However, Debian 10 has reached end-of-life and will no longer receive security updates. We strongly recommend upgrading to 3CX Version 20 (Debian 12) for ongoing security updates.

Technical Details

The update includes the following packages:

  • amd64/arm64 openssh-client 1:9.2p1-2+deb12u3
  • amd64/arm64 openssh-server 1:9.2p1-2+deb12u3
  • amd64/arm64 openssh-sftp-server 1:9.2p1-2+deb12u3
  • amd64/arm64 libarchive13 3.6.2-1+deb12u1

For a full list of packages and changes, please see the changelog.

Follow for updates in the community forum.