3CX Phone System Vulnerability Scan Remote Denial of Service Vulnerability
BID:36013
Info
3CX Phone System Vulnerability Scan Remote Denial of Service Vulnerability
| Bugtraq ID: | 36013 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-6895 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2008 12:00AM |
| Updated: | Aug 21 2009 05:32PM |
| Credit: | Chris Castaldo |
| Vulnerable: |
3CX Phone System 0 |
| Not Vulnerable: |
3CX Phone System 6.0.806.0 |
Discussion
3CX Phone System Vulnerability Scan Remote Denial of Service Vulnerability
3CX Phone System is prone to a denial-of-service vulnerability.
A remote attacker may exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to 3CX 6.0.806.0 are vulnerable; prior versions may also be affected.
3CX Phone System is prone to a denial-of-service vulnerability.
A remote attacker may exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to 3CX 6.0.806.0 are vulnerable; prior versions may also be affected.
Exploit / POC
3CX Phone System Vulnerability Scan Remote Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
3CX Phone System Vulnerability Scan Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
3CX Phone System Vulnerability Scan Remote Denial of Service Vulnerability
References:
References:
- Multiple vulnerabilities in 3CX 6.0.806.0 (Chris Castaldo)
- Vendor Homepage (3CX)