CVE-2019-1559

Status
Not open for further replies.

Peoria IT

Silver Partner
Advanced Certified
Joined
Jan 20, 2022
Messages
8
Reaction score
4
We have updated to v18 and PCI scan (pcicompliancemanager.com) detecting this vulnerability on our 3cx port 5001

TLS Padding Oracle Vulnerability (Zombie POODLE and GOLDENDOODLE)

No updates in Debian base OS.. false positive? can 3CX make a statement on this please?
Thanks!
 
This is clearly a false positive. V18 is running openssl 1.1.x which is not vulnerable.
 
  • Like
Reactions: Peoria IT
Hi @PEORIAIT,

Can you ensure that you have the option in the Management Console >> Security >> Anti-Hacking >>

"Enable PCI compliance SSL/SecureSIP Transport and Ciphers (This will leave only TLSv1.2 enabled and may prevent old legacy phones and old 3CX Apps to connect remotely to your system). Requires SIP service restart (Go to Dashboard, Services, Select 3CX PhoneSystem 01 SIP Server and restart)."

checked?
 
  • Like
Reactions: Peoria IT
Great, thanks! You shouldn't have to worry about anything else then @PEORIAIT. If you notice anything suspicious, feel free to update me.
 
  • Like
Reactions: Peoria IT
Hi @PEORIAIT,

Can you ensure that you have the option in the Management Console >> Security >> Anti-Hacking >>

"Enable PCI compliance SSL/SecureSIP Transport and Ciphers (This will leave only TLSv1.2 enabled and may prevent old legacy phones and old 3CX Apps to connect remotely to your system). Requires SIP service restart (Go to Dashboard, Services, Select 3CX PhoneSystem 01 SIP Server and restart)."

checked?
Thanks guys. Yes, that box is checked.
 
  • Like
Reactions: VasilisV_3CX
Hi
We have found this too after a recent PCI scan using a Qualys PCI scanning tool.
@VasilisV_3CX could you confirm that the weak cipher in question (ECDHE-RSA-AES256-SHA384) isn't used by the 3cx applications at all. We will need confirmation before we can submit a false positive statement.
Many thanks
Mark Allen
 
  • Like
Reactions: Peoria IT
Hello,
It is true that some ciphers allowed on HTTPS port are marked "weak" by such scanners however please note that the global SSL rank that Qualys issues is still an A+ so this isn't that severe of a finding, as such attacks require a man-in-the-middle to sit between client/server to be able to observe the oracle and also require obscure proprietary implementations of TLS whilst here we rely on a well known solution consisting of Nginx webserver and OpenSSL.

Furthermore, note that we have based the list of allowed ciphers on good practices from Mozilla as per OWASP recommendation in order to ensure the best compatibility with the wide variety of supported handsets and devices that needs to provision whilst still ensuring a high level of security.

So all in all you may ignore the said finding.
 
Can you provide a screenshot of SSL version or tell me how to generate one? Our PCI scan company is requiring this.
 
Answering my own question here and cli command "openssl version" prints that info.
 
  • Like
Reactions: VasilisV_3CX
Answering my own question here and cli command "openssl version" prints that info.
Is your 3cx install on windows? I can't find the openssl executable on my install?
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru