False positive False Positive: Security Metrics Vulnerability Scanner

BrenttG

Platinum Partner
Advanced Certified
Joined
Nov 17, 2017
Messages
912
Reaction score
586
Just thought i would submit this so 3CX can take action on it.

Security Metrics has an automated vulnerability scanner service that is bundled by several vendors for external scanning of IPs, and they are humorously mis-identifying Debian Linux 3CX servers as Microsoft IIS and ASP.NET stacks dating back to 2001 and calling them exploitable under CVE-2001-1248 and CVE-2007-3407, neither of which have anything to do with 3CX or Debian, its definitely a case of amateur hour with Security Metrics dev team not putting in proper relevance checking, however it has the risk of needlessly scaring people/customers/partners/etc into thinking there is a vulnerability present that is actually not, as well as telling them they are at high risk of information disclosure, and such.

For Reference, I personally installed this 3CX Server in question 2 years ago, it is 100% Debian Linux, it is one of our more prominent customers, there is no question of its platform, or any chance it is running on a windows server, i personally oversee this one as it is in a government setting.

1691446914326.png
 
Last edited:
Hello @BrenttG
Thank you for bringing this to our attention. We have already contacted Security Metrics. We will inform you of their response as soon as they get back to us. Our communication will remain transparent throughout this investigation.

Also please report this from your side contacting the Security Metrics support.
 
  • Like
Reactions: TheodorosG_3CX
We have done so, but zero reply yet....
 
Hi Brent, we have received a reply from the vendor, who informed us that since we are not the account holders, they cannot continue with us.

"In order to assist you further, we would need to receive your request for support from the primary email address on the account in question. "

Kindly contact them again from your side in order to continue with them to check this for you.
 
We are marking this as a false positive, as we notified the vendor, and they requested that the customer contact them. There is nothing further that can be done from our side.