The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://www.3cx.com/community/forums/posts-articles-news/ | vendor advisory |
https://packetstormsecurity.com/files/166376/3CX-Client-Missing-TLS-Validation.html | third party advisory vdb entry |