- Joined
- Jun 27, 2017
- Messages
- 42
- Reaction score
- 3
Hello,
Vulnerability details - https://nvd.nist.gov/vuln/detail/CVE-2023-2650
Microsoft Defender 365 is saying that 3CX is still using vulnerable Openssl libraries (version 3.1.0.0) which is libcrypto-3-x64.dll and libssl-3-x64.dll. Despite we are using the newest 3cx build 3CX Build 18.0.8.939 we are still vulnerable. I have checked those *.dll files and indeed they are still in the mentioned vulnerable version 3.1.0.0.
Those files are located under below path:
c:\program files\3cx phone system\bin\libcrypto-3-x64.dll
c:\program files\3cx phone system\bin\libssl-3-x64.dll
This vulnerability is CVSS 7.5 score which is High. This vulnerability was published on May 2023!!!
Could you tell all of us when you will update those vulnerable Openssl libraries that newest build of 3CX V18 is still using?
Vulnerability details - https://nvd.nist.gov/vuln/detail/CVE-2023-2650
Microsoft Defender 365 is saying that 3CX is still using vulnerable Openssl libraries (version 3.1.0.0) which is libcrypto-3-x64.dll and libssl-3-x64.dll. Despite we are using the newest 3cx build 3CX Build 18.0.8.939 we are still vulnerable. I have checked those *.dll files and indeed they are still in the mentioned vulnerable version 3.1.0.0.
Those files are located under below path:
c:\program files\3cx phone system\bin\libcrypto-3-x64.dll
c:\program files\3cx phone system\bin\libssl-3-x64.dll
This vulnerability is CVSS 7.5 score which is High. This vulnerability was published on May 2023!!!
Could you tell all of us when you will update those vulnerable Openssl libraries that newest build of 3CX V18 is still using?