CVE-2021-45491: Medium severity 3cx call flow designer vulnerability
Published Mar 28, 2022
·Updated
3CX System through 2022-03-17 stores cleartext passwords in a database.
Affected Software
1 affected component
3CX 3CX<=2022-03-17
Event History
Mar 28, 2022
CVE Published
via MITRE·01:14 AM
Data Sourced
via MITRE·01:14 AM
Description
Frequently Asked Questions
1
What is CVE-2021-45491?
CVE-2021-45491 is a vulnerability that allows 3CX System through 2022-03-17 to store cleartext passwords in a database.
2
How severe is CVE-2021-45491?
CVE-2021-45491 has a severity rating of 6.5 (Medium).
3
What software is affected by CVE-2021-45491?
3CX System versions up to and including 2022-03-17 are affected by CVE-2021-45491.
4
How can I fix the CVE-2021-45491 vulnerability?
To fix the CVE-2021-45491 vulnerability, update your 3CX System to a version that has the fix for this vulnerability.
5
Where can I find more information about CVE-2021-45491?
You can find more information about CVE-2021-45491 at the following references: [PacketStormSecurity](http://packetstormsecurity.com/files/166386/3CX-Phone-System-Cleartext-Passwords.html) and [3CX Community Forums](https://www.3cx.com/community/forums/posts-articles-news/).