ID

VAR-202203-0951


CVE

CVE-2021-45490


TITLE

3CX  of  Iphone_os  for  3cx  Certificate validation vulnerabilities in

Trust: 0.8

sources: JVNDB: JVNDB-2021-019061

DESCRIPTION

The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation. 3CX of Iphone_os for 3cx Exists in a certificate validation vulnerability.Information may be obtained and information may be tampered with. ############################################################# # # COMPASS SECURITY ADVISORY # https://www.compass-security.com/research/advisories/ # ############################################################# # # Product: 3CX Client for Windows (legacy), Android & iOS # Vendor: 3CX # CSNC ID: CSNC-2021-021 # CVE ID: CVE-2021-45490 # Subject: Missing Certificate Verification # CWE-ID: CWE-295 (Improper Certificate Validation) # Severity: Medium # Effect: Network Traffic Decryption and Manipulation # Author: Emanuel Duss <emanuel.duss@compass-security.com> # Date: 2022-03-17 # ############################################################# Introduction ------------ 3CX is an open-platform office phone system that runs on premise on Windows or Linux. 3CX was built for mobility, with remote work apps that offer secured communication for the whole team. These applications do not verify the TLS certificate of the 3CX server. - There is no fix from the vendor at the moment. - The new Electron based 3CX Desktop App is not affected. This allows an attacker between the 3CX application and the 3CX server to split the TLS traffic and therefore read and manipulate the transmitted data. For example, the data required for provisioning a new device can be read every time when the app is started. This data can then be used to provision another app. Thus, attackers can provision an own device and use the entire functionality of the app. This includes: - List companies in the phone book - Make phone calls - Listen to voice box - etc. This attack can for example be reproduced by performing an ARP spoofing attack in the network against the target client and by using Burp Suite as a transparent HTTP proxy. Vulnerability Classification ---------------------------- CVSS v3.1 Metrics [2]: - CVSS Base Score: 6.5 (Medium) - CVSS Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N Workaround / Fix ---------------- # 3CX Vendor The app should correctly verify the server's certificate using the system CA store or implement certificate pinning in the apps. # 3CX Users There is no security update for this vulnerability at the moment. According to the 3CX, the vulnerability will be tackled in future redesigns of the mobile apps. Users of the legacy Windows client can switch to the new Electron based 3CX Desktop App which is not affected. Timeline -------- 2021-12-16: Vulnerability discovered 2021-12-17: Discussed vulnerability with our customer Asked 3CX for security contact on Twitter, community forum, support email and contact form. Got response via support mail. Security contact was dpo@3cx.com Provided details Requested CVE ID @ MITRE 2021-12-25: Assigned CVE-2021-45490 2022-01-03: Asked vendor if they understood the vulnerability. Answer: Report was distributed internally. 2022-01-18: Asked vendor for any updates. 2022-02-02: Asked vendor for any updates. 2022-02-10: Asked vendor for any updates. 3CX can't tell when the issue will be fixed. 2022-03-11: Asked vendor for any updates. 3CX thanked for the report. Issues will be tackled in future redesigns of the mobile apps. 2022-03-17: Coordinated public disclosure Acknowledgement --------------- Thanks 3CX for the coordinated dicslosure. References ---------- [1] https://www.3cx.com/ [2] https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N&version=3.1

Trust: 1.71

sources: NVD: CVE-2021-45490 // JVNDB: JVNDB-2021-019061 // PACKETSTORM: 166376

AFFECTED PRODUCTS

vendor:3cxmodel:3cxscope:lteversion:18.0.11

Trust: 1.0

vendor:3cxmodel:3cxscope:lteversion:18.0.4

Trust: 1.0

vendor:3cxmodel:3cxscope:lteversion:2022-03-17

Trust: 1.0

vendor:3cxmodel:3cxscope:lteversion:2022-03-17 and earlier

Trust: 0.8

vendor:3cxmodel:3cxscope: - version: -

Trust: 0.8

vendor:3cxmodel:3cxscope:lteversion:18.0.4 and earlier

Trust: 0.8

vendor:3cxmodel:3cxscope:lteversion:18.0.11 and earlier

Trust: 0.8

vendor:3cxmodel:3cxscope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-019061 // NVD: CVE-2021-45490

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-45490
value: CRITICAL

Trust: 1.0

NVD: CVE-2021-45490
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202203-1927
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2021-45490
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2021-45490
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: CVE-2021-45490
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2021-019061 // CNNVD: CNNVD-202203-1927 // NVD: CVE-2021-45490

PROBLEMTYPE DATA

problemtype:CWE-295

Trust: 1.0

problemtype:Illegal certificate verification (CWE-295) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-019061 // NVD: CVE-2021-45490

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202203-1927

TYPE

trust management problem

Trust: 0.6

sources: CNNVD: CNNVD-202203-1927

EXTERNAL IDS

db:NVDid:CVE-2021-45490

Trust: 3.3

db:PACKETSTORMid:166376

Trust: 2.5

db:JVNDBid:JVNDB-2021-019061

Trust: 0.8

db:CNNVDid:CNNVD-202203-1927

Trust: 0.6

sources: JVNDB: JVNDB-2021-019061 // PACKETSTORM: 166376 // CNNVD: CNNVD-202203-1927 // NVD: CVE-2021-45490

REFERENCES

url:https://packetstormsecurity.com/files/166376/3cx-client-missing-tls-validation.html

Trust: 3.0

url:https://www.3cx.com/community/forums/posts-articles-news/

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2021-45490

Trust: 1.5

url:https://cxsecurity.com/cveshow/cve-2021-45490/

Trust: 0.6

url:https://www.compass-security.com/research/advisories/

Trust: 0.1

url:https://www.3cx.com/

Trust: 0.1

url:https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=av:n/ac:h/pr:n/ui:n/s:u/c:l/i:l/a:n&version=3.1

Trust: 0.1

sources: JVNDB: JVNDB-2021-019061 // PACKETSTORM: 166376 // CNNVD: CNNVD-202203-1927 // NVD: CVE-2021-45490

CREDITS

Emanuel Duss

Trust: 0.1

sources: PACKETSTORM: 166376

SOURCES

db:JVNDBid:JVNDB-2021-019061
db:PACKETSTORMid:166376
db:CNNVDid:CNNVD-202203-1927
db:NVDid:CVE-2021-45490

LAST UPDATE DATE

2024-11-23T23:00:53.184000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2021-019061date:2023-07-14T08:39:00
db:CNNVDid:CNNVD-202203-1927date:2022-04-06T00:00:00
db:NVDid:CVE-2021-45490date:2024-11-21T06:32:19.597

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2021-019061date:2023-07-14T00:00:00
db:PACKETSTORMid:166376date:2022-03-21T17:36:33
db:CNNVDid:CNNVD-202203-1927date:2022-03-21T00:00:00
db:NVDid:CVE-2021-45490date:2022-03-28T02:15:06.950