First published: Tue Jun 07 2022(Updated: )
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><space> followed by <shift><enter>" mishandling.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3cx Phone System Firmware | =16.0.0.1570 | |
3CX Phone System | ||
Debian Debian Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9972 is a vulnerability in 3CX Phone System (Debian based installation) 16.0.0.1570 that allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges.
CVE-2019-9972 has a severity rating of 8.8, which is considered critical.
The affected software for CVE-2019-9972 is 3CX Phone System firmware version 16.0.0.1570.
An authenticated attacker can exploit CVE-2019-9972 by using the "<space><space> followed by <shift><enter>" sequence to run arbitrary commands with phonesystem user privileges.
The vendor has released a patch for CVE-2019-9972, and users are advised to update to the latest version of 3CX Phone System firmware to mitigate the vulnerability.