security

  1. R.Larouche

    3CX Transcription: How to automatically mask sensitive data (PII)?

    Hello 3CX community, I would like to know if it is possible to configure or customize 3CX call transcription so that Personally Identifiable Information (PII) is automatically removed or masked from the final transcription text. For example, if a caller says a phone number, email address...
  2. Leo_B

    Changing session expiration timeout in v20

    Hello, Just discovered that 3CX v20 seems to provide the incredibly long timeout for web console session expiration (check the attached image). It looks like the default limit is set to some 60 days, which, to be honest, appears completely unacceptable. How can this value be changed? Thank you.
  3. Solved 3CX Product security

    https://www.3cx.com/pbx/security/ Based on the aforementioned article regarding the security of the 3CX system, would the service provider be able to issue official reports or certific. As our partner's security team seeks assurance regarding the security and reliability of the 3CX product.
  4. web client not accessible when chrome security is set to standard or optimized (AI)

    I can access my 3cx webclient within firefox but not with chrome. When I disable security, I can access the client. chrome://settings/security (set to disabled). When I enable standard or optimized (AI) the client cannot connect anymore. This happens only from the local lan. For example: when...
  5. Problem with 2FA for two different subscriptions with the same Ext

    Hi I manage a couple of subscriptions and have issues with 2FA. scenario Sub 1: Ext [email protected] Sub 2: Ext [email protected] 2FA authenticator:- Microsoft Authenticator when I enable 2FA for [email protected] , this overwrite the 2FA for [email protected] . and when enable 2FA for [email protected] , this overwrite...
  6. Initial restore to self hosted in AWS uses HTTP.

    MOD: Can't post to self hosted as "i need a self hosted system to do so" , could you move this thread please? When instantiating a server using the AWS marketplace listing, the initial login is http only. Anyone sending a backup of a system will be sending thir SIP trunk credentials in...
  7. Yealink T48U USB Port

    Hi All, After a security audit, we've been asked to turn off the USB ports on our 100+ Yealink T48U ports. I'd normally do this through a Template, but this customer is on a 3CX hosted solution. What are my options here? Best, Leigh
  8. Rick-Arcus-IT

    Possibility of using our own RPS with T53 router phone

    Hello, We are using our own Yealink RPS environment to monitor and control our Yealink phones. I tried to install a T53 router phone, but that didn't work because the phone was added to our own RPS server. After deleting the phone in our RPS, I could create the routerphone. but it still didn't...
  9. Can access to the admin console be restricted?

    Due to the attacks we have experienced, I need to know if it's possible to restrict the admin console for certain IP addresses, either through a Firewall-level VPN or something similar. If that's not possible, are you aware of any implementation that can be done to enhance security for access...
  10. Security on Chat / Password or PIN

    We are a healthcare company and are looking at using the 3CX Chat feature. Chat Apps like TigerText force the user to add a PIN and/or Password to their phones during installation. Is there anyway to secure the 3CX and chats from prying eyes by either forcing a login/pass on the phone itself or...
  11. System Owner to access Reports

    I have a user who wants to have daily reports sent to them and to be able to access the data from reports. I was unable to give them access until I set their role to System Owner. What's the lowest permission level we can use to gain access to reports and scheduling automated report emailing...
  12. SSO / Office 365 Integration Permissions

    From security perspective we would like to disallow the usage of Calendar Permissions in the App Registration permissions for the 3CX/Office 365 integration. But when we leave those permissions from the App Registration we are unable to continue. We would only like to use the Single Sign On...
  13. Multiple failed authentication timeouts from various IPs.

    We are trying to find ways to harden our hosted 3cx. We have had weeks now of " The IP has been blacklisted Reason: too many failed attempts." We are wondering if there is a way to have our public IP cycled or for additional hardening measures to take to prevent this from happening. Thanks,
  14. JamieLewisIBT

    Version on Management Console to include, Desktop App & Mobile App version

    This would be great as we are about to look at updating our kits but with the recent security issues we need to be sure what our customers are running without having to install the program, for obvious reasons.
  15. CVE-2019-14935 present in 3CXDesktopApp v18

    hi, CVE-2019-14935 from v15 of 3CXDesktopApp is still present in v18
  16. Chats always logged?

    Hello, working internal with an on-premise PBX (Professional license). After maintenance update to 18.0.5.418 we tested a bit the internal chat "feature". And i was shocked when i realised that all chats where protocolled since the PBX was installed while "chat protocol" was disabled. Did...
  17. CTK_Fabian

    compromised 3CX => calls to other countries

    Hi all, briefly about us we are a system house and run about 40 3CX-phonesystems at our customers with different installations. ( Windows / Linux / Cloud ) In 5 systems, we had in recent weeks various external calls to foreign numbers ( eg countries in Africa / etc. ) from different...
  18. [Security] Only allow softphone to work on internal network

    Hi, We have an issue whereby our sales and dispatch people share the QR code with others or call from home using their device. They have irregular schedules so it's hard to maintain a schedule within 3cx and disable external calls from an extension past working hours. We also have a lot of...
  19. Solved Direct SIP Question

    We are running the latest version of Debian 3CX - 18.0 (Build 461). We have an integration with Flowroute for our PSTN connectivity. Would it be beneficial, from a security perspective, to disable Direct SIP. In the 3CX MC, under Settings >> Network >> FQDN - we have Settings for Direct SIP...
  20. kinetix

    Signed / Trusted Updates for 3CX Upgrades

    With all the new Security being implemented throughout networks, would be great if 3CX would sign their updates with certificates which would allow executables and update downloads to run trusted by various security applications. Mike.