Packages and 3CX 18.0 Update 5

Status
Not open for further replies.

vcit

Premier Customer
Joined
Jan 30, 2023
Messages
8
Reaction score
0
My security ops team has some concerns with our 3CX installation. Many of the packages are falling out of date and the 3CX repos aren't updating them. Does anyone know if it's safe to update these adhoc? I don't want to break anything with our 3CX installation as this is our primary PBX, but in 2023 security should be a priority within any application.

Does anyone have any advice or guidance for this topic? I'll post the current list of CVEs below. It's in csv format but attached as a txt.
 

Attachments

  • Like
Reactions: vcit
From what 3CX has posted in the past, they don't support updating packages manually. If 3CX automatic updates are used to install 3CX updates, they will also update packages they want to update, when updating 3CX. If 3CX manual updates are used (auto updates are off), 3CX will not install other updates.

One other consideration is whether they are exploitable. For instance if someone is running vim on the 3CX server then there are probably larger concerns. :) (OTOH, updating vim seems unlikely to break 3CX)
 
  • Like
Reactions: vcit and Evolute IT
From what 3CX has posted in the past, they don't support updating packages manually. If 3CX automatic updates are used to install 3CX updates, they will also update packages they want to update, when updating 3CX. If 3CX manual updates are used (auto updates are off), 3CX will not install other updates.

One other consideration is whether they are exploitable. For instance if someone is running vim on the 3CX server then there are probably larger concerns. :) (OTOH, updating vim seems unlikely to break 3CX)
I do recall reading that about the packages, I was hoping there was solution that was in scope with 3CX.

I'll check with our Security team to see how this may affect our compliance audits.

Thank you for your responses.
 
Hello,
Some of our packages dependencies or those present by default in Debian indeed have a few updates pending, we have been actually reviewing them internally and once all validations will be completed those will be pushed to our repository. Just ensure that the option to Automatically update 3cx is ticked in your Management Console / Updates section with a preferred schedule configured.

That said I wouldn't be too much concerned about these, as SteveITS mentioned the question is if they are really exploitable, we keep an eye on those and they typically require a physical access or remote command access through SSH to be of any harm, which of course is the least of the concerns if a hacker already have this.
The base score of these CVEs need to be adjusted in the context of each application and use. Considering that external unauthenticated users will have a very limited attack surface, thanks to the default firewall rules and various others controls, and that authenticated ones also won't have any command execution capabilities those can all to be reranked to Low threats...
 
  • Like
Reactions: Nathan@Voxtelesys
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet