SSH Renegotiation DoS Vulnerability

Status
Not open for further replies.

Kwang Mien

Silver Partner
Advanced Certified
Joined
May 14, 2020
Messages
255
Reaction score
17
Hi All,

Recently, we ran VAPT test on our 3CX servers and there is SSL/TLS: Renegotiation DoS Vulnerability (CVE-2011-1473, CVE-2011-5094)

We are using 3cx Version 18 Update 7.

May I know how to fix this vulnerability ?

Thanks

Regards,
Kwang Mien
 
Hi Kwang,
Since you opened a support ticket on this same topic let's continue over there so we gather more info and advise accordingly.
 
@pj3cx
Would you post the solution back here please? Our security scanner also picks up on the old version of OpenSSH used on the Debian 3CX install. I would hope we can upgrade the OpenSSH parts without breaking anything?

2023-04- Debian 3CX OpenSSH vulnerabilities.png

Thanks
 
Ensure having the option to Auto-Update your 3cx system ticked so that dependencies and security updates are kept up-to date automatically. OpenSSH is a package taken from official Debian repositories, its latest version for buster distribution is 7.9p1-10+deb10u2. You can see the current status for known vulnerabilities in their tracker here: https://security-tracker.debian.org/tracker/source-package/openssh

When deploying a 3cx from the ISO you will get the latest Debian buster distribution along with latest version available for this package amongst others and it will come with a default configuration which is outside of our scope but can be customized if you like.
To reduce the attack surface of your system you may filter the TCP port 22 by firewall means upfront of the 3cx machine so that only trusted IP addresses from your administrators are allowed to connect in SSH.
 
Thanks PJ. I spent quite some time rechecking our (pfSense) firewall config - I had some settings incorrect. All good now - only the 3CX ports allowed.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet