Solved JAVA/Exploit.CVE 2022 22963 DETECTED

Status
Not open for further replies.

sbrammer

Forum User
Joined
May 18, 2017
Messages
51
Reaction score
10
We are running Eset for our Antivirus, and we received an Eset alert notification email that the above exploit was detected on our 3cx server and points to the 3cx management console.exe. Below are more details of the alert email we received.

computer_name: actual FQDN has been removed
severity: Warning
timestamp: 4/12/22, 12:01:35 PM CDT
src_ip_address: 127.0.0.1
src_address_type: IPv4
src_port: 61,099
tgt_address: 127.0.0.1
tgt_address_type: IPv4
tgt_port: 5,004
protocol: TCP
inbound_comm: yes
detection_name: JAVA/Exploit.CVE‑2022‑22963
rule_name:
process_name: C:\Program Files\3CX Phone System\Bin\3CXManagementConsole.exe
occurrences: 1
notification_name: Firewall Alerts

Our system is up to date and running 18.0 Update 3 (Build 461)

Can someone verify that 3cx is not vulnerable to this new Java exploit?

Thanks.
 
  • Like
Reactions: sbrammer
Hello,
We do not have any JAVA technology in the product nor dependency to Spring Cloud Function / SpEL so you can safely ignore this finding and mark it as false positive.
 
Why there is still installations of 3cx on windows ?? I don't get it...
 
thanks to all for the replies. I will pass them along to our network\security admin.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet