Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

3CX Urges Customers to Disable Integration Due to Potential Vulnerability

3CX tells customers to temporarily disable SQL Database integration to mitigate a potential vulnerability.

Business communication company 3CX is urging customers to disable SQL database integrations to prevent a vulnerability that occurs in certain configurations.

In a security advisory published on Friday, the company revealed that 3CX versions 18 and 20 are impacted by an integration bug.

“Only 0.25% of our user base have sequel integrated. It’s an old-style integration meant for an on-premise firewall secured network. Nevertheless, if you are using an SQL database integration, it’s subject potentially to a vulnerability – depending upon the configuration,” the company said.

According to 3CX, customers using MongoDB, MsSQL, MySQL, and PostgreSQL databases should disable their SQL database integrations until further notice.

“As a precautionary measure, and whilst we work on a solution to safely re-enable this integration, please follow the instructions below to disable it,” the company underlined.

To disable the integration, customers should go to the Settings section of the management console, go to CRM, set the available option to ‘None’, and save the modification.

Advertisement. Scroll to continue reading.

Web-based CRM integrations are not affected, 3CX says. The company has yet to provide technical details on the identified security defect.

In March this year, it came to light that North Korean hackers had compromised 3CX’s Windows and macOS build environments after an employee downloaded a trojanized application on their personal computer.

The supply chain attack led to malware being pushed to the company’s customers, with organizations in Europe and North America being impacted the most. 

More than 600,000 companies worldwide are using 3CX’s VoIP software.

Related: Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability

Related: CISA Offering Free Vulnerability Scanning Service to Water Utilities

Related: Recent NetScaler Vulnerability Exploited as Zero-Day Since August

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Mark Carter has been appointed Chief Information Security Officer at Socure.

Spektrum Labs has named Mark Cravotta Chief Operating Officer.

Philip Martin has joined Uber as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.