CVE-2022-28005
9.8
CRITICAL · CVSS 3.1 · EPSS 6.7% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjunction with a path component that uses backslash characters), leading to cleartext credential disclosure. Afterwards, the authenticated attacker is able to upload a file that overwrites a 3CX service binary, leading to Remote Code Execution as NT AUTHORITY\SYSTEM on Windows installations. NOTE: this issue exists because of an incomplete fix for CVE-2022-48482.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.73% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-522 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-05-06 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| 3cx | 3cx |
References
- https://medium.com/%40frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88
- https://www.3cx.com/blog/change-log/phone-system-change-log/
- https://www.3cx.com/blog/releases/v18-security-hotfix/
- https://www.3cx.com/blog/releases/v18-update-3-final/
- https://medium.com/%40frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88
- https://www.3cx.com/blog/change-log/phone-system-change-log/
- https://www.3cx.com/blog/releases/v18-security-hotfix/
- https://www.3cx.com/blog/releases/v18-update-3-final/
→ the Explorer · watch your stack · NVD