Tag: security

Avoid walking the plank with expired modules

With the recent brisk pace of FreePBX security improvements, we are seeing increased reports in our community forums and elsewhere from users who are encountering issues when modules won’t upgrade to the latest version or stop working in subtle ways because of out-of-date third-party pseudo-mirrors.

Read More »

Watch what we do with security fixes 👀

This article discusses meta-issues surrounding security fixes in FreePBX, investigates vulnerability scoring tools, and offers some ideas for improvements. System Administrators should walk away with a better understanding of terms like CVE, CWE, CVSS (including the differences between Base and other metrics), and EPSS.

Read More »

FreePBX Security Issues SEC-2023-001 and SEC-2023-002

Summary: Ensure that all FreePBX/PBXact modules are up to date Always monitor and follow up on security notifications from your PBX Ensure that you are on supported FreePBX/PBXact version 15 or greater EOL versions of FreePBX/PBXact (14 or older) do not get security updates or bug fixes! Security Vulnerability SEC-2023-001 Hello all. By now, administrators

Read More »

Keep an Eye on the Dashboard

This past week saw two noteworthy threads posted to the FreePBX community forum separated by a few days; independent reports of a “Tampered File Warning” showing up in the FreePBX dashboard. This warning is connected to a core security feature of FreePBX. In FreePBX (and PBXact) each module is published with a signature, and in

Read More »
Scroll to Top