Outage in Sherweb

Security Incident for Sangoma based PBX's

Minor
September 19, 2023 - Started 13 days ago
Official incident page

Need to monitor Sherweb outages?
Stay on top of outages with IsDown. Monitor the official status pages of all your vendors, SaaS, and tools, including Sherweb, and never miss an outage again.
Start a Free Trial

Outage Details

Our Cloud Security team is investigating an active security vulnerability with the Sangoma Phone system, which would affect customers using our Enterprise PBX platform (not CloudPBX or PBXPro).We have been in touch with Sangoma and they have not yet released a security patch for this issue. We are awaiting information from them on this. In the meantime, we have put some initial measures in place to limit the potential for any malicious activity and to help protect our clients.As a result of these protective measures, certain Phone Apps features are not functioning as intended. While we recognize that this is not ideal, our aim with these changes is to make sure that clients are protected against the evolving security threats.In situations where a certain functionality has been lost due to these protective measures, the impacted functionality can be restored on a case-by-case basis. This would mean, however, that the new security measures would no longer be in place, so this would be done at your own risk.We ask for your patience as we work diligently with our partners to get more clarity on this new security vulnerability, so we can best determine the next steps. We are actively monitoring the situation and will provide a further update once more information is available.
Components affected
Sherweb Dedicated VM PBX Hosts
Latest Updates ( sorted recent to last )
INFORMATIONAL 15 days ago - at 09/17/2023 04:00AM

Our Cloud Security team is investigating an active security vulnerability with the Sangoma Phone system, which would affect customers using our Enterprise PBX platform (not CloudPBX or PBXPro).We have been in touch with Sangoma and they have not yet released a security patch for this issue. We are awaiting information from them on this. In the meantime, we have put some initial measures in place to limit the potential for any malicious activity and to help protect our clients.As a result of these protective measures, certain Phone Apps features are not functioning as intended. While we recognize that this is not ideal, our aim with these changes is to make sure that clients are protected against the evolving security threats.In situations where a certain functionality has been lost due to these protective measures, the impacted functionality can be restored on a case-by-case basis. This would mean, however, that the new security measures would no longer be in place, so this would be done at your own risk.We ask for your patience as we work diligently with our partners to get more clarity on this new security vulnerability, so we can best determine the next steps. We are actively monitoring the situation and will provide a further update once more information is available.

Monitor Sherweb and all your third-party dependencies in one place

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 2763 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook

Setup in 5 minutes or less

Try it out! How much time you'll save your team, by having the outages information close to them?

  • 14-day free trial
  • No credit card required to start
  • Cancel anytime
  • +2500 services available