Security Alert for Systems with IP Based SIP Trunks

Pierre_3CX

Staff member
3CX Support
Joined
Aug 1, 2013
Messages
781
Reaction score
401

Hackers are becoming smarter at thwarting IP based security. Upgrade to Update 8A immediately.​

IP based SIP Trunk users are increasingly at risk of hacker attacks. Recently we have seen a surge in techniques and methods which can circumvent systems with loosely configured security. If you haven’t locked down your IP based SIP trunk f...
Continue reading the Original Blog Post.
 
Will 3CX instances that rely on IP based security only need to make any configuration changes once this update is applied?
 
No changes required whatsoever, just update to latest version Update 8A.
 
No changes required whatsoever, just update to latest version Update 8A.
On it

Just FYI (you probably know), Version 20.0 Update 9 (Build 670 Alpha) did not get an update (will there be one?)

Also, on some systems got the English prompt update to 4.0.6 (not to all of them)

Thank you Team!
 
Last edited:
@Pierre_3CX will there be a hotfix for Update 9 Alpha, or does it already have the new protections?
 
Does this only affect IP based trunks which are running over public internet?
Or does this also affect IP based trunks running over private networks (3cx <-> mpls / ipsec <-> provider)?
What is the attack vector (if you could disclose more details, of course)?
 
I’m curious about the 8A update—does this attack exploit the default open port 5060? In other words, do hackers use this port to place calls via an IP-based SIP trunk, which could be categorized as illegal calls?
 
  • Like
Reactions: NCIA and rc@cn
It would be helpful to have more details on what the attack scenario involves. Is the issue related to the 3CX Webclient being exploited, which could mean that any system exposed on port 443 is at risk, or is there a different scope to this situation?
 
Same questions on our end.
 
  • Like
Reactions: GigCityCloud
If you haven’t locked down your IP based SIP trunk
What did you exactly mean by that?

Without technical details, it is not clear whether our clients are actually at risk or not.

Can this problem be mitigated just by sensible firewall / IP trunk configuration?
Or problem in PBX logic, and it can be resolved only by this patch?
 
Hi all, It has already been quite a while.

I noticed that after installing Update 8A, a new option was added to the trunks and it is disabled by default:
"Allow Carrier Side Transfers (SIP REFER)".

I assume this may be related to the security vulnerability. Without claiming that this is the exact issue being addressed, it does seem like a plausible connection.

Sending the REFER:
The attacker sends a SIP REFER request with a Refer-To header pointing to an international premium-rate number,
for example: Refer-To: sip:[email protected]

But I am not claiming anything, as I did not verify the SIP packet contents prior to the update, and I cannot confirm whether this feature was enabled in the unpatched version 20.0.8. I don't know if that this feature (SIP REFER) was enabled by default in version 20.0.8 .

In any case, the update only takes a few seconds.
Restarting the server takes longer than applying the micro-update itself.


Good day !

1774984572648.png
 
As per the blog post, you should update immediately to update 8A if you have an IP based SIP trunk that is connected to the internet. Register based SIP trunks are not effected as they use authentication.

Its possible that your VoIP provider has mitigated the risk already (most voip providers will block premium numbers in "remote" countries), or you might have configured outbound rules (blocking premium number destinations at PBX level) or inbound rule configuration made it impossible for it to be an issue but clearly there are many configurations and combinations out there. Its related to outbound calls. Its not related to any type of system access.

So you need to install the update if you have an IP based SIP trunk. All the Hosted by 3CX systems have been updated already.
 
Last edited:
I'm assuming fqdn authentication is the same thing correct? can we get more info on what the attack involves? was there a hardening configuration we could apply before this update to prevent this attack surface?
 
We have 3CX instances behind hardware firewalls that will only allow traffic on port 5060 from the SIP provider, and the SIP provider will only allow 5060 traffic from the 3CX instance's public IP. Are these safe?
 
Last edited by a moderator:
I'm assuming fqdn authentication is the same thing correct? can we get more info on what the attack involves? was there a hardening configuration we could apply before this update to prevent this attack surface?
No FQDN authentication is not the same thing. Register based SIP trunks have authentication
 
We have 3CX instances behind hardware firewalls that will only allow traffic on port 5060 from the SIP provider, and the SIP provider will only allow 5060 traffic from the 3CX instance's public IP. Are these safe?
You need to update to update 8A as per the blog post.
 
I'm not seeing 8A ??
Current version is: 20.0.8.1121
With options in System/Updates only for Alpha: New 20.0 Update 9 20.0.9.670
Am I missing something?
 
  • Like
Reactions: NatalyS_3CX and N_G
20.0.8.1121 probably is v20 Update 8a
 
  • Like
Reactions: N_G
  • Like
Reactions: N_G

Members Online Now

Forum statistics

Threads
111,832
Messages
589,285
Members
164,662
Latest member
DejanMDS