Solved CVE-2023-2650

Status
Not open for further replies.

CodeTwo

Customer
Joined
Jun 27, 2017
Messages
42
Reaction score
3
Hello,

Vulnerability details - https://nvd.nist.gov/vuln/detail/CVE-2023-2650

Microsoft Defender 365 is saying that 3CX is still using vulnerable Openssl libraries (version 3.1.0.0) which is libcrypto-3-x64.dll and libssl-3-x64.dll. Despite we are using the newest 3cx build 3CX Build 18.0.8.939 we are still vulnerable. I have checked those *.dll files and indeed they are still in the mentioned vulnerable version 3.1.0.0.

Those files are located under below path:
c:\program files\3cx phone system\bin\libcrypto-3-x64.dll
c:\program files\3cx phone system\bin\libssl-3-x64.dll

This vulnerability is CVSS 7.5 score which is High. This vulnerability was published on May 2023!!!
Could you tell all of us when you will update those vulnerable Openssl libraries that newest build of 3CX V18 is still using?
 
Can't speak for windows, but on Debian 10 the the 1.1.1n is also affected, because Debian does not provide the 1.1.1u package with the fix. In Debian 12 (v20) we have a fixed version
 
That looks odd.
Is MS Defender looking at the client version on a windows workstation??
I don't see those files on my workstation at all.
Do you have the latest Desktop App installed?
Have just checked and downloaded the latest Desktop App installer from the webclient page and I get 3CXDesktopApp-18.13.959.msi.

The 18.0 Update 8 (Build 939) is the Server version from my console which is the latest.
 
Hello,

In the upcoming v18 Update 9 for Windows these DLL files no longer exist and our binaries ship an updated OpenSSL version already so this is addressed.

However, the postgreSQL folder also includes a similar version that is "vulnerable".
Note that in our context the risk associated is considered Very Low as this library encrypts the SSL communication taking place between 3cx processes and the database server and both are running on localhost. An external attacker cannot access the database directly nor tamper with this communication.
Nevertheless we are considering an update to latest postgreSQL so that such old dependencies aren't caught by automated scans anymore.

On Linux this is also addressed already for v18 Update 8 and above as there were security updates published on our downloads repository for the libssl package. Admins just needs to ensure the Automatic Updates option is enabled so that their system remains up-to-date and secure.
 
Status
Not open for further replies.

Forum statistics

Threads
111,819
Messages
589,168
Members
164,642
Latest member
davids86