Off the top of my head, I would say:
- Attacks on the phone itself (primarily http/https) to steal access data or install a backdoor.
- Manipulation of the phone via fake provisioning information.
- Exploiting zero-day vulnerabilities (dns, ntp, etc.).
- Use of the captured data for fraud or to carry out further attacks on the local infrastructure.
Disclaimer: The use of EOL devices always carries a certain risk and one can only try to minimize the possible attack surfaces and effects.
Regardless of EOL status, I would recommend strict network segmentation for telephones.
In other words, place all telephones in a separate VLAN, with the firewall only allowing absolutely necessary communication between the SBC and the 3CX and the telephones and the 3CX (HTTPS for provisioning).
Replace external services (DNS, NTP) with your own/trusted servers where possible (e.g., the TIME_NTP_SERVER parameter for the phones).
No access between the phone VLAN and the rest of the network!
This may involve a loss of convenience: Block connections to external provisioning servers (RPS).
Secure the possibility of physical access to the telephone VLAN (MAC filter, avoid using the LAN port on the telephone, etc.).