vulnerability

  1. Content Security Policy (CSP) issue or bypass

    Dear 3CX Community, -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Description A vulnerability has been detected on https://xxxxxxxxxxxxxx:5001 Some issues have been...
  2. Insecure HTTP download of preseed file by installer

    The official Debian installer ISO of 3CX v20 downloads a Debian installer preseed file via unencrypted HTTP from http://downloads-global.3cx.com/downloads/debian12iso/preseed_12.1.0_46a7ea2.txt This is configured as a boot parameter for the ISO via the "url=" parameter Download is unencrypted...
  3. wars

    Crowdstrike Endpoint Security Detection re 3CX Desktop App

    Hey, (Posted this in the wrong section so deleted and moved it here) So, we use Crowdstrike Falcon Overwatch and about half an hour ago I had an alert come through (something which only happens a handful of times a year) telling me that the 3CX Desktop App has been attempting to communicate...
  4. Solved CVE-2022-28005 CVSS 9.8 in 3CX V16 - when hotfix will be available ?

    Hello, I would like to know if there will be hotfix, patch available for 3CX V16 version ? There are plenty of users with V16 of 3CX. The Vulnerability is pretty dangerous with CVSS 9.8 - https://www.opencve.io/cve/CVE-2022-28005 On official 3CX page there is information that support for V16...
  5. foobar

    Security Contact

    Hello I'm looking for a security contact at 3CX. I did not find any information on the pubic website, security.txt, in the customer dashboard or somewhere else. I also don't want to buy a support ticket. Is there a email address where I can reach technical people of 3CX regarding their...
  6. v16 ? sipXtapi INVITE Message CSeq Field Header Remote Overflow ( CVE: CVE-2006-3524)

    Does upgrading to latest C3X version on SIP devices remediate the following vulnerability: sipXtapi INVITE Message CSeq Field Header Remote Overflow ( CVE: CVE-2006-3524) See also https://www.tenable.com/plugins/nessus/22092 https://seclists.org/fulldisclosure/2006/Jul/161...