peter bassill · operator
$ cve CVE-2022-28005 JSON

CVE-2022-28005

9.8
CRITICAL · CVSS 3.1 · EPSS 6.7% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjunction with a path component that uses backslash characters), leading to cleartext credential disclosure. Afterwards, the authenticated attacker is able to upload a file that overwrites a 3CX service binary, leading to Remote Code Execution as NT AUTHORITY\SYSTEM on Windows installations. NOTE: this issue exists because of an incomplete fix for CVE-2022-48482.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.73% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-522
On CISA KEVno
Public exploitnone known
Published2022-05-06
Last modified2026-06-17

Affected (1)

VendorProduct
3cx3cx

References

→ the Explorer  ·  watch your stack  ·  NVD