PCI scan failed (CVE-2021-3618 - ALPACA Issue)

Status
Not open for further replies.

3CXusername

Joined
Jul 31, 2014
Messages
186
Reaction score
17
* Running the latest Linux 18.0 (Build 908)
* PCI compliance enabled on system (SSL/SecureSIP Transport and Ciphers)
* using Let's Encrypt cert
* openssl version 1.1.1n 15 Mar 2022

Anyone else have this issue when doing PCI scanning? Is there a fix?

Our scan vendor says to upgrade to latest version of application: This vulnerability has been fixed in the following versions:
vsftpd 3.0.4
nginx 1.21.0
sendmail 8.17

1678982240608.png

thanks
 
Hi,

Are you sure you are running the latest stable version of 3CX? (18.0.6.908)

The version of nginx which is patched against this vulnerability is 1.14.2-2+deb10u5 and has been in our repository since the release of U6.

Bash:
nginx:
  Installed: 1.14.2-2+deb10u5
  Candidate: 1.14.2-2+deb10u5
  Version table:
 *** 1.14.2-2+deb10u5 500
        500 http://repo.3cx.com/debian-security/1806 buster/main amd64 Packages
        100 /var/lib/dpkg/status

This is one of the reasons we urge people to always keep 3CX up to date.
 
Simple answer is to take the 3CX server out of your CDE then it doesn't have to pass.
 
That version of nginx is the latest version for this release of Debian. It is patched against this CVE. There is no further update for 3CX to take besides for updating to a newer version of Debian. 3CX doesn't make Debian or nginx.

You scanning tool is incorrect here.
Yes I know 3CX doesn't make Debian or nginx but they can still update newer NGINX version in repository
Hi,

Are you sure you are running the latest stable version of 3CX? (18.0.6.908)

The version of nginx which is patched against this vulnerability is 1.14.2-2+deb10u5 and has been in our repository since the release of U6.

Bash:
nginx:
  Installed: 1.14.2-2+deb10u5
  Candidate: 1.14.2-2+deb10u5
  Version table:
 *** 1.14.2-2+deb10u5 500
        500 http://repo.3cx.com/debian-security/1806 buster/main amd64 Packages
        100 /var/lib/dpkg/status

This is one of the reasons we urge people to always keep 3CX up to date.
Instance was current as of yesterday 18.0.6.908. So it is up to date (as stated in my OP). See update 7 is out now. What version of ngnix is included there?

Simple answer is to take the 3CX server out of your CDE then it doesn't have to pass.
So that is what you do in your secure environment just remove inscope items? ;)
 
Yes I know 3CX doesn't make Debian or nginx but they can still update newer NGINX version in repository
The newest version of nginx for this version of Debian is the version already installed.
Instance was current as of yesterday 18.0.6.908. So it is up to date (as stated in my OP). See update 7 is out now. What version of ngnix is included there?
The same version
So that is what you do in your secure environment just remove inscope items? ;)
No. The version of nginx in 3CX is secure, your scanner is incorrect here. Either fix your scanner or remove it from the scan or deal with the warning.
 
The newest version of nginx for this version of Debian is the version already installed.

The same version

No. The version of nginx in 3CX is secure, your scanner is incorrect here. Either fix your scanner or remove it from the scan or deal with the warning.
thanks for confirm.
 
So that is what you do in your secure environment just remove inscope items? ;)
If it doesn't need to be in-scope then yes! Obviously if something does have to be in-scope then it needs to be resolved.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet