V20 Product Security Assessment from Mandiant - a Part of Google Cloud - Now Published

N_G

Founder
Joined
Jun 6, 2006
Messages
4,857
Reaction score
9,291

Quantifying investment in product security assessment of 3CX V20 phone system core services by Mandiant.​

As part of our ongoing commitment to product security, 3CX engaged Mandiant, a part of Google Cloud and leader in cybersecurity consulting, to conduct a thorough, multi-phase security assessment of the 3CX Phone System V20. ...
Continue reading the Original Blog Post.
 
Last edited by a moderator:
Well done 3CX ;) Thank you for this status:)
 
It's fantastic to see your commitment to security :)

Well done 3CX Team!
 
BRAVO 3CX Team!
Keep up the amazing work!
 
Are the HIGH and CRITICAL vulnerabilities found in earlier versions going to get a CVE (and said CVE score?)

I ask this as I work for a SOC / MSP, and if we or our customers run old software, we can also show them also basic information on CVEs that the end-user (customer) is using out-of-date software with (remote code) exploits possible.

Usually, at the latest 30 to 90 days after the vulnerability was found the CVE gets made/posted (esp. since the fix is already available by updating to the latest available version).
 
No, they will not and its not needed either. They need to be on the latest software.
 

Latest Posts

Forum statistics

Threads
111,991
Messages
590,166
Members
164,929
Latest member
Cloudstar