{"id":23772,"date":"2022-03-24T00:36:00","date_gmt":"2022-03-23T23:36:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=23772"},"modified":"2022-03-31T13:11:56","modified_gmt":"2022-03-31T11:11:56","slug":"schwachstelle-in-windows-3cx-telefonanlagen-patchen-ist-angesagt","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/03\/24\/schwachstelle-in-windows-3cx-telefonanlagen-patchen-ist-angesagt\/","title":{"rendered":"Vulnerability in Windows 3CX telephone systems"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/03\/24\/schwachstelle-in-windows-3cx-telefonanlagen-patchen-ist-angesagt\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Anyone running a 3CX system (telephone system) under Windows in a version below v18 Update 3 (Build 450) should react. The manufacturer has released a security update for this product in the form of v18 Update 3 (Build 450).<\/p>\n<p><!--more--><\/p>\n<h2>The 3CX system<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg02.met.vgwort.de\/na\/2974fa96989a41ea865fde348a6db793\" alt=\"\" width=\"1\" height=\"1\" \/><a href=\"https:\/\/en.wikipedia.org\/wiki\/3CX_Phone_System\" target=\"_blank\" rel=\"noopener\">3CX<\/a> is a software-based private branch exchange (PBX). The 3CX PBX is based on the SIP (Session Initiation Protocol) standard. The solution allows extensions to make calls over the Public Switched Telephone Network (PSTN) or via Voice over Internet Protocol (VoIP) services on-site, in the cloud or via a cloud service operated by 3CX. The 3CX Phone System is available for Windows, Linux and Raspberry Pi[ and supports standard SIP soft\/hardphones, VoIP services, faxes, voice and web meetings, and traditional PSTN phone lines. Details can be found on the <a href=\"https:\/\/www.3cx.com\/\" target=\"_blank\" rel=\"nofollow noopener\">manufacturer's website<\/a>.<\/p>\n<h2>Vulnerability in PBX software<\/h2>\n<p>Blog reader Liam contacted me by email back in the middle of the month and pointed out a security update for 3CX systems (thanks for that). He received the following notice from this manufacturer.<\/p>\n<blockquote><p>Dear Liam,<\/p>\n<p>Our records indicate that you are using a Windows-based 3CX System below v18 Update 3 (Build 450). 3CX systems below this version have been subjected to a security vulnerability.<\/p>\n<p>We are not aware of any exploitation of this vulnerability to date, and therefore we will not disclose further details of the vulnerability at the moment. This is to protect yourselves and other customers from possible malicious attacks. The reporting entity has also agreed to withhold publicly disclosing the CVE until <b>21st March 2022<\/b>.<\/p>\n<p>We urge you to upgrade your 3CX System to <a href=\"https:\/\/www.3cx.com\/blog\/releases\/v18-update-3-final\/\" target=\"_blank\" rel=\"noopener\">v18 Update 3<\/a> (Build 450) or higher as soon as possible, in order to keep your installation secure.<\/p>\n<p><b>To upgrade to V18 Update 3<\/b><\/p>\n<p>Click on \"Updates\" in the Management Console's Dashboard, select \"v18 Update 3 Final\" and click on \"Download Selected\" to install this update on your PBX.<\/p>\n<p>Regards,<\/p>\n<p>The 3CX Team<\/p><\/blockquote>\n<p>In the meantime, however, there is <a href=\"https:\/\/www.3cx.com\/blog\/change-log\/phone-system-change-log\/\" target=\"_blank\" rel=\"noopener\">3CX Version 18, Hotfix 1 (Security &amp; Memory), Build 18.0.3.461 March 2022<\/a> released to fix vulnerabilities.<\/p>\n<p><strong>Addendum:<\/strong> The early feedback from readers was that this software had long since been patched and not too much people are still using the software. I cannot make a final judgement, as I do not know\/use the product.<\/p>\n<p><a href=\"https:\/\/twitter.com\/frycos\/status\/1509290015133773832\" target=\"_blank\" rel=\"noopener external noreferrer\" data-wpel-link=\"external\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" title=\"3CX vulnerability\" src=\"https:\/\/i.imgur.com\/8cdOj1N.png\" alt=\"3CX vulnerability\" width=\"587\" height=\"564\" \/><\/a><\/p>\n<p>But I came across the above <a href=\"https:\/\/twitter.com\/frycos\/status\/1509290015133773832\" target=\"_blank\" rel=\"noopener\">tweet<\/a> and <a href=\"https:\/\/medium.com\/@frycos\/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88\" target=\"_blank\" rel=\"noopener\">this article<\/a> on Medium on 31 March 2022. User @frycos simply used the search engine Shodan to check the availability of the \"3CX Phone System Management Console\" from the internet. Over 203 thousand instances were found, of which over 31,600 installations are running in Germany &#8211; so it seems rather untrue that no one is still using it. In any case, @frycos took a close look at his installation and describes how he was able to take the system apart in terms of security via the 3CX Phone System Management Console.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Anyone running a 3CX system (telephone system) under Windows in a version below v18 Update 3 (Build 450) should react. The manufacturer has released a security update for this product in the form of v18 Update 3 (Build 450).<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,1547,22],"tags":[69,1544,195],"class_list":["post-23772","post","type-post","status-publish","format-standard","hentry","category-security","category-software","category-update","tag-security","tag-software","tag-update"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/23772","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=23772"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/23772\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=23772"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=23772"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=23772"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}