Solved 3CX Appliance and SBC flagging for CVE-2020-15778

Status
Not open for further replies.

AlexWilliams

Bronze Partner
Advanced Certified
Joined
Jan 11, 2023
Messages
4
Reaction score
3
Hi Team,
Our security team has identified that our 3CX box and SBC are both flagging as running less than OpenSSH 8.3 as part of CVE-2020-15778

Are you able to confirm if 3CX is vulnerable to CVE-2020-15778, we are running 18.0 (Build 939)
 
  • Like
Reactions: jed
Hi Alex,

Let me first clarify that it is not the 3CX software that is flagged but the openssh package running on it.

Regarding the vulnerability itself, it is an authenticated command injection vulnerability, meaning that it requires that you already have access to the server in order to exploit it, by executing specific scp payloads.

The Openssh team aknowledged the issue, however due to a high possibility of breaking existing workflows they decided not to address it as the fix could cause more problems than the existence of the vulnerability.

You can find more information about the packages here: https://security-tracker.debian.org/tracker/CVE-2020-15778
 
Status
Not open for further replies.

Forum statistics

Threads
111,819
Messages
589,168
Members
164,642
Latest member
davids86