- Joined
- Nov 17, 2017
- Messages
- 912
- Reaction score
- 586
Just thought i would submit this so 3CX can take action on it.
Security Metrics has an automated vulnerability scanner service that is bundled by several vendors for external scanning of IPs, and they are humorously mis-identifying Debian Linux 3CX servers as Microsoft IIS and ASP.NET stacks dating back to 2001 and calling them exploitable under CVE-2001-1248 and CVE-2007-3407, neither of which have anything to do with 3CX or Debian, its definitely a case of amateur hour with Security Metrics dev team not putting in proper relevance checking, however it has the risk of needlessly scaring people/customers/partners/etc into thinking there is a vulnerability present that is actually not, as well as telling them they are at high risk of information disclosure, and such.
For Reference, I personally installed this 3CX Server in question 2 years ago, it is 100% Debian Linux, it is one of our more prominent customers, there is no question of its platform, or any chance it is running on a windows server, i personally oversee this one as it is in a government setting.

Security Metrics has an automated vulnerability scanner service that is bundled by several vendors for external scanning of IPs, and they are humorously mis-identifying Debian Linux 3CX servers as Microsoft IIS and ASP.NET stacks dating back to 2001 and calling them exploitable under CVE-2001-1248 and CVE-2007-3407, neither of which have anything to do with 3CX or Debian, its definitely a case of amateur hour with Security Metrics dev team not putting in proper relevance checking, however it has the risk of needlessly scaring people/customers/partners/etc into thinking there is a vulnerability present that is actually not, as well as telling them they are at high risk of information disclosure, and such.
For Reference, I personally installed this 3CX Server in question 2 years ago, it is 100% Debian Linux, it is one of our more prominent customers, there is no question of its platform, or any chance it is running on a windows server, i personally oversee this one as it is in a government setting.

Last edited: