CVE-2021-45490

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
28/03/2022
Last modified:
04/04/2022

Description

The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:3cx:3cx:*:*:*:*:*:iphone_os:*:* 18.0.4 (including)
cpe:2.3:a:3cx:3cx:*:*:*:*:*:android:*:* 18.0.11 (including)
cpe:2.3:a:3cx:3cx:*:*:*:*:legacy:windows:*:* 2022-03-17 (including)