Gotta love the mindless PCI Compliance scanners that simply check versions numbers from the connection banner and red flag anything that isn't bleeding edge, most of those companies wouldn't know anything about security if it bit them in the fanny. All they usually tell us is, if the scan passes, you are secure, if it fails, you are not secure, flow chart speak, and most of them are using 3rd party scan tools that they themselves have zero understanding of, not even their own tools...
For the time being,
@kieferschild has given you good advise. Its not a bad idea to keep 3CX on a seperate IP not only for this reason, but for many other reasons as well. Then this is less of an issue.