Solved Vulnerability Scanning

Status
Not open for further replies.

rclocherty

Premier Customer
Joined
Jun 9, 2021
Messages
18
Reaction score
2
Hi there

We have around 16 self hosted 3CX instances running on Debian. Our vulnerability scanner is now reporting a huge amount of vulnerabilities on all of them. Each of them are running the latest 3CX release but i am aware that these don't always include Debian updates. Reading through the documentation from 3CX it looks like if i manually update these instances then i forfeit support from 3CX. How are other people getting around this and what is 3CX official 'line' on this?
 
  • Like
Reactions: NCIA
Debian updates are pushed and done with 3CX updates if you use automatic update on 3CX pbxs
 
I have auto updates configured on all instances. Do the servers need to be rebooted with this process or will it restart automatically or not required?

Thanks
 
Last edited:
Hi, We're currently testing the latest security patches, and they will be out soon, possibly within the next week.

Please ensure that the systems have the option enabled to receive automatic updates and set a time that will be out of office hours for them to receive the updates. In the same cases, depending on the security patches that are pushed out, a restart may be required, which will be done automatically.
 
  • Like
Reactions: ArneDery
Thanks for the update. Could there be a reason as to why none of my instances have picked up the previous security updates even though they are set to automatically download?

Thanks
 
  • Like
Reactions: NCIA
Ah ok, that would make sense, we only enabled the option around 2 months ago. Is there any way to manually do this or when the next 3CX update is released would it do all of them together?

Thanks for your quick responses!
 
Systems will periodically check automatically, and when there are updates that are not applied, it will apply them.
 
Is there a way to check logs to see what Debian updates have installed or the last time they installed any? One of the Vulnerabilities we are seeing is that the Debian Os is unsupported now. My concern is that without that update i will receive no other security patches.

Thanks
 
The updates can be seen in the system logs, /var/log/unattended-upgrades/.
 
Do you know if the next security update will include all previous updates also?
 
The system will automatically check for all updates that have not been applied and will apply them between the times set in the automatic updates section. Any new updates will also be applied when released.
 
  • Like
Reactions: ArneDery
So all of my 3cx instances have auto updates configured for the weekend, The weekend has been and gone and no Debian updates have been installed.

Could you advise?
 
As per previous replies the last major update was in July while some additional have been applied in October. Keep in mind that the OS updates should also be tested from our side and we are looking into the matter. We will share additional details when they become available.
 
  • Like
Reactions: Charles_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,819
Messages
589,168
Members
164,642
Latest member
davids86