CVE-2022-28005: Critical severity 3cx call flow designer vulnerability
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjunction with a path component that uses backslash characters), leading to cleartext credential disclosure. Afterwards, the authenticated attacker is able to upload a file that overwrites a 3CX service binary, leading to Remote Code Execution as NT AUTHORITY\SYSTEM on Windows installations. NOTE: this issue exists because of an incomplete fix for CVE-2022-48482.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28005?
CVE-2022-28005 is a vulnerability discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.
What is the severity of CVE-2022-28005?
The severity of CVE-2022-28005 is critical with a CVSS score of 9.8.
How does CVE-2022-28005 affect the 3CX phone system?
CVE-2022-28005 allows an unauthenticated attacker to abuse improperly secured access and gain unauthorized access to arbitrary files on the server.
How can I fix CVE-2022-28005?
To fix CVE-2022-28005, it is recommended to upgrade the 3CX Phone System Management Console to version 18 Update 3 FINAL or apply the necessary security hotfix.
Where can I find more information about CVE-2022-28005?
You can find more information about CVE-2022-28005 in the provided references: [link1], [link2], [link3].