PT-2022-8314 · 3Cx · 3Cx Phone System

Published

2022-06-07

·

Updated

2022-06-14

·

CVE-2019-9972

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 3CX Phone System versions 16.0.0.1570
Description The issue allows an authenticated attacker to execute arbitrary commands with the phonesystem user privileges due to the mishandling of a specific input sequence, namely " followed by ".
Recommendations For version 16.0.0.1570, consider restricting access to the PhoneSystem Terminal to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the privileges of the phonesystem user to reduce potential damage from arbitrary command execution.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9972

Affected Products

3Cx Phone System