CVE-2021-45490
3CX 3CXPhone vulnerability analysis and mitigation

Overview

The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation (NVD, CVE). The vulnerability was assigned CVE-2021-45490 and was discovered in December 2021.

Technical details

The vulnerability has been assigned a CVSS v3.1 Base Score of 9.1 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). The vulnerability is related to improper certificate validation (CWE-295) in the client applications, affecting multiple platforms including Windows, iOS and Android versions through March 17, 2022 (NVD).

Impact

The lack of SSL certificate validation could allow attackers to intercept and manipulate communications between the client and server, potentially leading to information disclosure and integrity breaches. The vulnerability affects confidentiality and integrity of communications, though availability is not impacted (NVD).

Mitigation and workarounds

Users should upgrade to versions released after March 17, 2022, which include proper SSL certificate validation. The vulnerability affects the following versions: 3CX for Windows (legacy) versions up to 2022-03-17, 3CX for iOS versions up to 18.0.4, and 3CX for Android versions up to 18.0.11 (NVD).

Additional resources


SourceThis report was generated using AI

Related 3CX 3CXPhone vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-49954CRITICAL9.8
  • 3CX 3CXPhone3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesDec 25, 2023
CVE-2023-27362HIGH7.8
  • 3CX 3CXPhone3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMay 03, 2024
CVE-2023-29059HIGH7.8
  • 3CX 3CXPhone3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMar 30, 2023
CVE-2022-48483HIGH7.5
  • 3CX 3CXPhone3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMay 02, 2023
CVE-2022-48482HIGH7.5
  • 3CX 3CXPhone3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMay 02, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management