medium.com
https://medium.com/%40frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88 CVE-2022-28005
CRITICAL
3cx 3cx Insufficiently Protected Credentials
Record summary
CVE-2022-28005 has a selected CVSS score of 9.8 (critical).
Description
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjunction with a path component that uses backslash characters), leading to cleartext credential disclosure. Afterwards, the authenticated attacker is able to upload a file that overwrites a 3CX service binary, leading to Remote Code Execution as NT AUTHORITY\SYSTEM on Windows installations. NOTE: this issue exists because of an incomplete fix for CVE-2022-48482.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 25, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
References
6medium.com
https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-28005 3cx.com
https://www.3cx.com/blog/change-log/phone-system-change-log 3cx.com
https://www.3cx.com/blog/releases/v18-security-hotfix 3cx.com
https://www.3cx.com/blog/releases/v18-update-3-final