Skip to content

Latest ZAC Version 9.2 – Now Available for All Zultys Deployments  Download Update Now

Connect With an Expert: 888-985-8971

Connect With an Expert: 888-985-8971

  • Contact Zultys Support
  • Get a Quote
  • Login
    • Customer Billing
  • Contact Zultys Support
  • Get a Quote
  • Login
    • Customer Billing
Zultys logo
  • Products

    Unified Communications

    • ZAC
    • Mobile ZAC

    Integrated Contact Center

    Business Phone Systems

    • Zultys Cloud Services
    • On-Premise and Virtual
    • Hardware as a Service

    Application Integration

    Phones and Accessories

    • ZIP 49GA IP Phone
    • ZIP 47GE IP Phone
    • ZIP 45G IP Phone
    • Z 23GE IP Phone
    • Z 22G IP Phone
    • Z 21i IP Phone
    • Gateways

    FEATURED PRODUCT

    Integrated Contact Center

    Optimize operations, efficiently manage high call volume, increase customer engagement, and improve the customer service experience.

    Contact representative on the phone with a customer
    Learn More
  • Solutions

    Industry

    • Healthcare
    • Education
    • Professional Services & Tech
    • Real Estate
    • Retail & Automotive

    Business Type

    • Small Business
    • Multi-Location
    • Enterprise

    FEATURED

    Zultys Case Studies and Videos

    Get insight into our Partner and customer community and their experiences using the Zultys UC solution.

    Learn More
    Person accessing Zultys case studies through mobile and laptop
  • Resources

    Product Resources

    • Videos & Tutorials
    • User Manuals
    • FAQs
    • ZCS Service Status
    • Product Flyers & Brochures

    Company Resources

    • Case Studies
    • News & Blog
    • Technologies We Work With

    FEATURED

    Zultys MX System Release 18.2 & ZAC 9.2

    Make sure you’re getting all Zultys has to offer by updating to the latest version.
    Learn More
    Person updating computer to latest version
  • Partner With Us
  • Contact Zultys Support – Zultys
  • Get a Quote
  • Request Demo
  • Customer Billing
Request Demo

SAN23-001

Zultys Security Advisory Notice - SAN23-001 Rev 2.0

Unauthorized Administrative Access Vulnerabilities (CVE-2023-43742, CVE-2023-43743, CVE-2023-43744)

Severity: Critical
Published: 2023-10-05
Updated: 2023-10-30
Revision: 2.0

Impacted Products

MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, MX30

Affected Releases

MX firmware 3.2.10 to 17.0.10

Introduction

Several security vulnerabilities in the MX platform were responsibly reported to Zultys and subsequently detailed in CVE-2023-43742, CVE-2023-43743 and CVE-2023-43744. Patches are available for MX Release 16.0.4 and 17.0.10 to remediate the vulnerabilities.

Description

CVE-2023-43742 – The service that runs on TCP port 7505 used by MX Administrator is vulnerable to authentication bypass. An anonymous attacker on the Internet can gain full administrative access without valid credentials.

CVE-2023-43743 – The web-based administration service on TCP port 443 is vulnerable to SQL injection. Web-based administration service is present in MX firmware 16.0.4 and later.

CVE-2023-43744 – The MX Administrator Patch Manager service allows remote authenticated users to perform OS command injection attacks. Users with administrator level access to the system can use this to execute OS commands on the underlying host.

Resolution

The actions required to protect a system via a firmware upgrade and/or a patch vary depending on the firmware version that an MX system is currently running.

Firmware Action
17.0.10
Install patch 17161 (or later replacement) via Patch Manager
17.0.6 Upgrade to 17.0.10 and install patch 17161 (or later replacement) via Patch Manager
16.0.4
Install patch 16109 (or later replacement) via Patch Manager
16.0.2
Upgrade to a supported release (16.0.4 or 17.0.10) and patch
15.0.x and earlier
Upgrade to a supported (16.0.4 or 17.0.10) and patch
If the current firmware is more than 2 major releases prior to the target release, a multi-step upgrade must be performed. Refer to the MX firmware release notes for additional details.
MX systems running release 16.0.4 or 17.0.10 that have Scheduled Patching enabled, will be automatically patched based on their configured patching schedule. Additional information about the patches is available from the Knowledge Base System (https://kbs.zultys.com)

A system must be covered by a current Software Subscription or Software Assurance agreement to be eligible to upgrade firmware.

Release 17 does not support MXIE, users still utilizing MXIE must move to ZAC if upgrading from Release 16 or earlier to Release 17.0.10.

Mitigation / Workaround

If it is not immediately possible to upgrade or patch a system, access should be denied to the relevant services from untrusted IP addresses using the MX ‘Service Protection – Source Based Firewall’ feature where available (Release 14.0.4+) or block access to the relevant ports from untrusted IP addresses using an external firewall.

Services Ports Applicable to Version
HTTPS 443
16.0.x, 17.0.x
MX Admin
MXIE
7117, 7134, 7505
All Versions

Acknowledgements

Zultys would like to thank Stephen Breen of Atredis Partners for reporting these issues to us.

Change Log

RevisionDateChanges
1.0

2023-10-05

Initial Security Advisory Notice.

1.1

2023-10-13

Patch numbers updated. Patch 17159 replaced by 17161. Patch 16107 replaced by 16109
2.0

2023-10-30

Details of CVE numbers added. Content updated accordingly.

KBS

This SAN is also available via KBS (https://kbs.zultys.com) FAQ issue ID ‘fq-5171’.

Contact

If additional information is required contact support@zultys.com or your Authorized Zultys Channel Partner.

Download PDF
Back to Security Advisories >

Get started with smarter communications today.

Request Demo
Request Quote
Zultys logo

Products

  • Unified Communications
  • ZAC
  • Mobility
  • Integrated Contact Center
  • Phones and Accessories

Platforms

  • Zultys Cloud Services
  • On-Premise and Virtual

Resources

  • Videos & Tutorials
  • User Manuals
  • FAQs
  • ZCS Service Status
  • Speedtest
  • Product Flyers & Brochures
  • Case Studies

Company

  • About Us
  • News & Blog
  • Careers
  • Contact Us
Linkedin Facebook-f Twitter
Linkedin Facebook-f Twitter Youtube

Copyright ©2006 – 2025 Zultys, Inc. All Rights Reserved

Legal | Privacy​ | Cookie Policy​ | Sitemap
Website Terms and Conditions | Privacy Policy​ | Legal | Sitemap
You’ll get a reply shortly. We typically reply in a few minutes

Connecting with agent...

Please introduce yourself and post your question to start live chat


By engaging in this chat, you hereby grant consent for Zultys to use and retain the content of this conversation.

Thank you for chatting with us. We are always happy to help you!

Are you sure you want to leave the chat? Connection with the agent will be lost