CVE-2019-9972: Command Injection
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><space> followed by <shift><enter>" mishandling.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9972?
CVE-2019-9972 is a vulnerability in 3CX Phone System (Debian based installation) 16.0.0.1570 that allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges.
How severe is CVE-2019-9972?
CVE-2019-9972 has a severity rating of 8.8, which is considered critical.
What is the affected software for CVE-2019-9972?
The affected software for CVE-2019-9972 is 3CX Phone System firmware version 16.0.0.1570.
How can an attacker exploit CVE-2019-9972?
An authenticated attacker can exploit CVE-2019-9972 by using the "<space><space> followed by <shift><enter>" sequence to run arbitrary commands with phonesystem user privileges.
Are there any fix or mitigation steps for CVE-2019-9972?
The vendor has released a patch for CVE-2019-9972, and users are advised to update to the latest version of 3CX Phone System firmware to mitigate the vulnerability.