CVE-2019-9971: Critical severity 3cx phone system firmware vulnerability
Published Jun 7, 2022
·Updated
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password. This occurs because the -z (aka postrotate-command) option to tcpdump can be unsafe when used in conjunction with sudo.
Affected Software
3 affected components
3CX Phone System Firmware=16.0.0.1570
3CX Phone System
Debian Debian Linux
Event History
Jun 7, 2022
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-9971.
2
What is the severity of CVE-2019-9971?
The severity of CVE-2019-9971 is critical with a CVSS score of 8.8.
3
How can an attacker exploit CVE-2019-9971?
An attacker can exploit CVE-2019-9971 by using sudo with the tcpdump command without a password.
4
What is the affected software of CVE-2019-9971?
The affected software is 3CX Phone System (Debian based installation) version 16.0.0.1570.
5
Is 3CX Phone System (non-Debian based installation) vulnerable to CVE-2019-9971?
No, 3CX Phone System (non-Debian based installation) is not vulnerable to CVE-2019-9971.