SSH Vulnerability

Status
Not open for further replies.

Lee Cramman

Premier Customer
Advanced Certified
Joined
Jul 9, 2018
Messages
694
Reaction score
166
We've received an alert from Google for some of our cloud VMs including our 3CX PBX - https://cloud.google.com/compute/do...2.80944734.-891374208.1718789885#gcp-2024-040

Due to some issues with upgrading, we're still on V18u9.

We do, of course, have SSL blocked at the firewall except during maintenance. I am aware that trying to manually patch this is a bad idea as we may end up with an unsupported configuration.

I was wondering if we could get some official reassurance that this vulnerability has been patched in all supported 3CX configurations, as long as automatic updates are switched on.

Thanks
 
For v18 there are no security updates anymore. Anyway, as long as your port is closed from WAN, its no problem.
 
For v18 there are no security updates anymore. Anyway, as long as your port is closed from WAN, its no problem.
Ouch, no more OS security updates for a supported configuration? Is that a Deb thing or a 3CX thing?

Port 22 is closed from WAN while not conducting maintenance... I'm about to conduct some maintenance, wondering what the exposure is.
 
  • Like
Reactions: Lee Cramman
From what I've seen it's so far been proven against 32 bit not 64 bit. Here's an ex-Twitter thread posted on the patchmanagement.org list.
Thanks Steve. The install is getting nuked and restored to V20 soon(ish), so this is a short-term problem for us, but that is reassuring.

After today I think I can keep port 22 blocked until we're running V20.
 
Can you just allow your current source IP in the router/firewall?
Sadly, we're stuck behind a private network provided by the NHS which my organisation does not control. My origin point can appear to be any one of many gateway IP addresses and I have no way of accessing that list of IPs to whitelist them.

We do have secondary broadband (for VOIP) with a static IP, I suppose I could whitelist that and connect that way...

But it's probably just easier to leave the enable-ssh rule completely turned off until I need access, which (after today) hopefully shouldn't be until we're running V20.
 
https://www.bleepingcomputer.com/ne...-openssh-rce-bug-gives-root-on-linux-servers/

AFIAK

"
The regreSSHion flaw impacts OpenSSH servers on Linux from version 8.5p1 up to, but not including 9.8p1.


Versions 4.4p1 up to, but not including 8.5p1 are not vulnerable to CVE-2024-6387 thanks to a patch for CVE-2006-5051, which secured a previously unsafe function.


Versions older than 4.4p1 are vulnerable to regreSSHion unless they are patched for CVE-2006-5051 and CVE-2008-4109."

I checked one of my v18's and it was running 7.9p1 so i'd assume yours in the same?
 
https://www.bleepingcomputer.com/ne...-openssh-rce-bug-gives-root-on-linux-servers/

AFIAK

"
The regreSSHion flaw impacts OpenSSH servers on Linux from version 8.5p1 up to, but not including 9.8p1.


Versions 4.4p1 up to, but not including 8.5p1 are not vulnerable to CVE-2024-6387 thanks to a patch for CVE-2006-5051, which secured a previously unsafe function.


Versions older than 4.4p1 are vulnerable to regreSSHion unless they are patched for CVE-2006-5051 and CVE-2008-4109."

I checked one of my v18's and it was running 7.9p1 so i'd assume yours in the same?
Ah the irony - I had to enable SSH to check!

Yes, we're on OpenSSH_7.9p1 :)

Thank you for passing that on to me.
 
  • Like
Reactions: bitn2
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,951
Messages
589,886
Members
164,843
Latest member
sambannoura