Let me first clarify that it is not the 3CX software that is flagged but the openssh package running on it.
Regarding the vulnerability itself, it is an authenticated command injection vulnerability, meaning that it requires that you already have access to the server in order to exploit it, by executing specific scp payloads.
The Openssh team aknowledged the issue, however due to a high possibility of breaking existing workflows they decided not to address it as the fix could cause more problems than the existence of the vulnerability.