4
CVSSv2

CVE-2021-45491

Published: 28/03/2022 Updated: 31/03/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

3CX System through 2022-03-17 stores cleartext passwords in a database.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

3cx 3cx

Recent Articles

3CX teases security-focused client update, plus password hashing
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources As Mandiant finds more evidence it was North Korea wot done it

The CEO of VoIP software provider 3CX has teased the imminent release of a security-focused upgrade to the company’s progressive web application client. “Following our Security Incident we've decided to make an update focusing entirely on security,” CEO Nick Galea wrote on Monday. In case you missed it, that incident was a late March supply chain attack that saw the company’s Windows Electron desktop app compromised by malware. Galea said Alpha and Beta releases of the updated client wil...