- Joined
- Aug 26, 2009
- Messages
- 38
- Reaction score
- 8
Had a pen test done of the network and a lot of issues were raised with weak SSL on Snom320.
I understand these are end of life but any opinions on if this actually causes a potential security issue?
Also raised that SSLv3 is enabled on a Yealink T42S, which is a supported, upto date model. It also supports weak and medium strength cipher suites, weak hashing algorithm & EXPORT_RSA (FREAK) vulnerability.
This seems more concerning, is this todo with the phone, 3CX specific firmware or the provisioning? Will this be addressed with the update supporting S-RTP, etc. or will these weaknesses remain?
I understand these are end of life but any opinions on if this actually causes a potential security issue?
Also raised that SSLv3 is enabled on a Yealink T42S, which is a supported, upto date model. It also supports weak and medium strength cipher suites, weak hashing algorithm & EXPORT_RSA (FREAK) vulnerability.
This seems more concerning, is this todo with the phone, 3CX specific firmware or the provisioning? Will this be addressed with the update supporting S-RTP, etc. or will these weaknesses remain?