Vulnerabilities CVE-2021-23017

Status
Not open for further replies.

Jack Ng

Customer
Joined
Apr 28, 2022
Messages
3
Reaction score
0
Hi everyone,

Is there any solution to fix for Vulnerabilities CVE-2021-23017? Our security scanner found that the 3CX nginx services are having critical vulnerability.

Remark: Our 3CX is running on latest V18 version
1651105917363.png.

Your support would be very much appreciated.
 
It may be that the version of nginx that 3CX uses is vulnerable to this CVE, but cannot be exploited. I haven't checked fully, but...

A remote attacker can cause a worker process to stop responding, denying access to some users. This vulnerability is present only if one or more resolver directives have been configured. By default, no resolvers are configured.
So if 3CX has not configured a resolver directive, then this can be ignored for now (till a software update)
 
Meaning to say it can be consider as false positive for now?
 
Meaning to say it can be consider as false positive for now?
I haven't checked how 3CX configured nginx. You can check or wait until someone else weighs in.
 
Would you mind to advise how could I check on how 3CX configured NGINX?
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,900
Latest member
Silent_Guru