Inbound UDP port 9034 exposed by Realtek Jungle SDK Remote Code Execution Vulnerability

Status
Not open for further replies.

cpe90

Customer
Joined
Mar 7, 2023
Messages
78
Reaction score
19
Is anyone else getting this threat warning from your firewall?
We are using Palo Alto FW, and this port has been hit constantly by bad actors trying to expose IOT devices.
https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/

This port is only required if we use SIP Trunk / VOIP Provider, but I do not think we need it if we are hosting it on-premise.
But the 3CX firewall check will fail if we don't allow this inbound UDP port.

1683648060674.png

I'm curious to see what others are doing in your on-prem environment.
Do you let the 3CX firewall check to fail by not opening the ports, or do you still allow them even though you're not using them and ignoring the firewall threat warning for the sake of passing the 3CX firewall test?

And also, I wish 3CX would tell us from what IP this firewall check is coming from because they used IP addresses from all over the world and I'm only allowing US-based connections so most of the time the firewall test will fail anyway.

Thank you, guys, for your feedback.
 
Would also like to know what the best course of action is here.
 
Couple options here:

1. Understand that the PA is giving a false positive and ignore it. Obviously there isn't a vulnerable software at that port if the port is going to 3CX
2. If you are not using a SIP trunk (perhaps you are using a PRI with a converter like a Patton), close the port range after running a firewall check and getting green. If you need to run the check again in the future, open it up, run the check, close it again.
3. If you are using a SIP trunk, closing that port (or the range) can lead to calls with no audio. In which case you can make 3CX unsupported and change the RTP port range in 3CX.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,973
Messages
590,075
Members
164,895
Latest member
jasonkkrause