CVE-2022-48482
3CX 3CXPhone vulnerability analysis and mitigation

Overview

3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allowed unauthenticated remote attackers to read certain files via /Electron/download directory traversal. The vulnerability could expose sensitive information including credentials, full backups, call recordings, and chat logs (NVD).

Technical details

The vulnerability existed in the ManagementConsoleJS.Provisioning.ElectronController class, specifically in the Download method accessible via /download/{platform}/{file} endpoint. The issue stemmed from improper validation of user-controlled parameters in Path.Combine() calls, allowing directory traversal attacks. Attackers could exploit this by using Windows backslash character as directory separator, which nginx would forward unmodified (Medium Blog).

Impact

The vulnerability allowed attackers to access sensitive files within C:\ProgramData\3CX\Instance1\Data and its subdirectories. This included access to credentials stored in cleartext, chat logs, call recordings, and complete backups of the 3CX installation (Medium Blog).

Mitigation and workarounds

The vulnerability was patched in 3CX Version 18, Update 2 Security Hotfix, Build 18.0.2.315 released in February 2022. The fix introduced checks through Utilities.IsVulnerablePath(file) to validate file paths and prevent directory traversal attacks (3CX Changelog).

Additional resources


SourceThis report was generated using AI

Related 3CX 3CXPhone vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-49954CRITICAL9.8
  • 3CX 3CXPhone3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesDec 25, 2023
CVE-2023-27362HIGH7.8
  • 3CX 3CXPhone3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMay 03, 2024
CVE-2023-29059HIGH7.8
  • 3CX 3CXPhone3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMar 30, 2023
CVE-2022-48483HIGH7.5
  • 3CX 3CXPhone3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMay 02, 2023
CVE-2022-48482HIGH7.5
  • 3CX 3CXPhone3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMay 02, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management