3CX - DesktopApp Security Alert
Incident Report for Netmatters
Resolved
This incident has been resolved.
Posted May 10, 2023 - 12:23 BST
Update
Netmatters have now updated customers' 3CX phone systems to Version 18 update 7 on the latest release.

All Netmatters customers on Version 18 update 7 can now use the desktop/MAC app as required moving forward.
Posted May 10, 2023 - 12:23 BST
Update
Netmatters have been keeping a close eye on the recent vulnerability relating to 3CX.

3CX has advised that the new Windows electron app Update 7 Windows Electron App build number 18.12.424 has been checked by their advisors Mandiant who found no evidence of compromise. Due to certificate changes, they had to update the naming convention. They re-opened the build to address this. Build 18.12.425 has been created and released.

Netmatters customers on Version 18 update 7 have already been updated to the latest release and can now use the desktop/MAC app as required moving forward.

In relation to the next steps, as Version 18 Update 7 and the related apps have been checked by 3CX advisors Mandiant we will be looking to update the majority of our 3CX customers, apart from any that have requested to not be updated just yet to Version 7.

We are looking at completing the update week commencing 8th May and will advise on the confirmed update date on this has been confirmed.
Posted Apr 19, 2023 - 15:23 BST
Update
Netmatters have continued to monitor the vulnerability relating to 3CX

3CX has now advised that the new windows electron app Update 7 Windows Electron App build number 18.12.424 has been checked by their advisors Mandiant who found no evidence of compromise. Due to certificate changes, they had to update the naming convention. They re-opened the build to address this. Build 18.12.425 has been created and released.

Therefore Netmatters customers on Version 18 update 7 have been updated to the latest release and can now use the desktop app as required moving forward.

Netmatters customers utilising version numbers 18.11.1213, 18.12.402, 18.12.407 & 18.12.416 for Mac Users will need to update their phone system to Update 7 to have the new fix released to them. Netmatters will be contacting any customers with MAC users on this version to discuss a date and time the update can be completed.

Netmatters will then be looking at rolling out the latest 3cx update to non-impacted customers over the coming weeks and will be in contact when it has been confirmed when this will be completed
Posted Apr 11, 2023 - 15:38 BST
Update
Netmatters are still monitoring the vulnerability relating to 3CX.

Netmatters are still aware this is in relation to Version 18, Update 7 for Desktop App users. Version numbers 18.12.407 & 18.12.416 for Windows installs and version numbers 18.11.1213, 18.12.402, 18.12.407 & 18.12.416 for Mac Users have been highlighted as potential issues.

Again, it’s important to state that the majority of Netmatters 3CX customers are still on Version 6 as Netmatters conduct a staged update process before updating our managed systems accordingly, so most clients are not affected and any impacted customers have been contacted directly.

3CX has advised that for customers on Version 18 update 7, a secure approved build for Windows will soon be released and once this has been released Netmatters will push the approved version out to any customers on Version 7.

In relation to MAC users, we are still reviewing this with 3CX and as soon as a resolution is put in place we will action this accordingly.
Posted Apr 06, 2023 - 14:17 BST
Update
Netmatters are still monitoring the vulnerability relating to 3CX.

Netmatters are still aware this is in relation to Version 18, Update 7 for Desktop App users. Version numbers 18.12.407 & 18.12.416 for Windows installs and version numbers 18.11.1213, 18.12.402, 18.12.407 & 18.12.416 for Mac Users have been highlighted as potential issues.

Any customers that are on Version 7 have been contacted by Netmatters to ensure that steps are being taken to protect their systems along with Mac desktop app version 18.11.1213 for Version 6.

We are continuing to monitor this with 3CX and as soon as we have a further update or resolution we will advise accordingly.

We would like to thank our customers for their patience on this matter.
Posted Apr 04, 2023 - 16:04 BST
Monitoring
Netmatters are still monitoring the vulnerability relating to 3CX.

Netmatters are still aware this is in relation to Version 18, Update 7 for Desktop App users. Version numbers 18.12.407 & 18.12.416 for Windows installs and version numbers 18.11.1213, 18.12.402, 18.12.407 & 18.12.416 for Mac Users have been highlighted as potential issues.

As previously outlined any customers that are on Version 7 who utilise the Desktop App have been contacted by Netmatters to ensure that steps are being taken to protect their systems along with Mac desktop app version 18.11.1213 for Version 6.

We are continuing to monitor this with 3CX and as soon as we have a further update or resolution we will advise accordingly.

We would like to thank our customers for their patience on this matter.
Posted Apr 03, 2023 - 11:15 BST
Identified
Netmatters are currently aware of a vulnerability relating predominantly to 3CX. This is in relation to Version 18, Update 7 for Desktop App users. Version numbers 18.12.407 & 18.12.416 for Windows installs and version numbers 18.11.1213, 18.12.402, 18.12.407 & 18.12.416 for Mac Users have been highlighted as potential issues.

At this stage, it’s important to state that the majority of Netmatters 3CX customers are still on Version 6 as Netmatters conduct a staged update process before updating our managed systems accordingly, so most clients are not affected. By not deploying the newest version as soon as they are released allows us to conduct testing of new versions and review the feedback from those partners that update immediately.

Any customers that are on Version 7 who utilise the Desktop App have been contacted by Netmatters to ensure that steps are being taken to protect their systems along with Mac desktop app version 18.11.1213 is available on Version 6.

We will continue to monitor the issue and updates from 3CX and will continue to provide any required updates via the status page.
Posted Mar 31, 2023 - 10:26 BST
This incident affected: VoIP Phone Systems.