10

CVE-2021-44228

Warning
Exploit

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Data is provided by the National Vulnerability Database (NVD)
Siemens6bk1602-0aa12-0tp0 Firmware Version < 2.7.0
   Siemens6bk1602-0aa12-0tp0 Version-
Siemens6bk1602-0aa22-0tp0 Firmware Version < 2.7.0
   Siemens6bk1602-0aa22-0tp0 Version-
Siemens6bk1602-0aa32-0tp0 Firmware Version < 2.7.0
   Siemens6bk1602-0aa32-0tp0 Version-
Siemens6bk1602-0aa42-0tp0 Firmware Version < 2.7.0
   Siemens6bk1602-0aa42-0tp0 Version-
Siemens6bk1602-0aa52-0tp0 Firmware Version < 2.7.0
   Siemens6bk1602-0aa52-0tp0 Version-
ApacheLog4j Version >= 2.0.1 < 2.3.1
ApacheLog4j Version >= 2.4.0 < 2.12.2
ApacheLog4j Version >= 2.13.0 < 2.15.0
ApacheLog4j Version2.0 Update-
ApacheLog4j Version2.0 Updatebeta9
ApacheLog4j Version2.0 Updaterc1
ApacheLog4j Version2.0 Updaterc2
SiemensCapital Version < 2019.1
SiemensCapital Version2019.1 Update-
SiemensCapital Version2019.1 Updatesp1912
SiemensComos Version < 10.4.2
SiemensE-car Operation Center Version < 2021-12-13
SiemensEnergy Engage Version3.1
SiemensEnergyip Version8.5
SiemensEnergyip Version8.6
SiemensEnergyip Version8.7
SiemensEnergyip Version9.0
SiemensEnergyip Prepay Version < 3.8.0.12
SiemensGma-manager Version < 8.6.2j-398
SiemensIndustrial Edge Management Hub Version < 2021-12-13
SiemensMindsphere Version < 2021-12-16
SiemensNavigator Version < 2021-12-13
SiemensNx
SiemensOpcenter Intelligence Version >= 3.2 < 3.5
SiemensOperation Scheduler Version <= 1.1.3
SiemensSentron Powermanager Version4.1
SiemensSentron Powermanager Version4.2
SiemensSiguard Dsa Version >= 4.2 < 4.4.1
SiemensSipass Integrated Version2.80
SiemensSipass Integrated Version2.85
SiemensSiveillance Command Version <= 4.16.2.1
SiemensSiveillance Identity Version1.5
SiemensSiveillance Identity Version1.6
SiemensSolid Edge Harness Design Version2020 Update-
SiemensSolid Edge Harness Design Version2020 Updatesp2002
SiemensSpectrum Power 4 Version < 4.70
SiemensSpectrum Power 4 Version4.70 Update-
SiemensSpectrum Power 4 Version4.70 Updatesp7
SiemensSpectrum Power 4 Version4.70 Updatesp8
SiemensSpectrum Power 7 Version < 2.30
SiemensSpectrum Power 7 Version2.30
SiemensSpectrum Power 7 Version2.30 Update-
SiemensSpectrum Power 7 Version2.30 Updatesp2
SiemensVesys Version < 2019.1
SiemensVesys Version2019.1
SiemensVesys Version2019.1 Update-
SiemensVesys Version2019.1 Updatesp1912
SiemensVesys Version2020.1 Update-
SiemensVesys Version2021.1 Update-
IntelDatacenter Manager Version < 5.1
IntelOneapi Sample Browser Version- SwPlatformeclipse
IntelSystem Studio Version-
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
DebianDebian Linux Version11.0
FedoraprojectFedora Version34
FedoraprojectFedora Version35
SonicwallEmail Security Version < 10.0.13
NetappActive Iq Unified Manager Version- SwPlatformlinux
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappActive Iq Unified Manager Version- SwPlatformwindows
NetappCloud Insights Version-
NetappCloud Manager Version-
NetappCloud Secure Agent Version-
NetappOncommand Insight Version-
NetappOntap Tools Version- SwPlatformvmware_vsphere
NetappSnapcenter Version- SwPlatformvmware_vsphere
CiscoAutomated Subsea Tuning Version < 2.1.0
CiscoBroadworks Version < 2021.11_1.162
CiscoBusiness Process Automation Version < 3.0.000.115
CiscoBusiness Process Automation Version >= 3.1.000.000 < 3.1.000.044
CiscoBusiness Process Automation Version >= 3.2.000.000 < 3.2.000.009
CiscoCloud Connect Version < 12.6\(1\)
CiscoCloudcenter Version < 4.10.0.16
CiscoCloudcenter Cost Optimizer Version < 5.5.2
CiscoCloudcenter Suite Admin Version < 5.3.1
CiscoCloudcenter Workload Manager Version < 5.5.2
CiscoCommon Services Platform Collector Version >= 2.10.0 < 2.10.0.1
CiscoContact Center Domain Manager Version < 12.5\(1\)
CiscoContact Center Management Portal Version < 12.5\(1\)
CiscoCrosswork Data Gateway Version < 2.0.2
CiscoCrosswork Data Gateway Version3.0.0
CiscoCrosswork Network Controller Version < 2.0.1
CiscoData Center Network Manager Version < 11.3\(1\)
CiscoDna Center Version < 2.1.2.8
CiscoDna Center Version >= 2.2.2.0 < 2.2.2.8
CiscoDna Center Version >= 2.2.3.0 < 2.2.3.4
CiscoEmergency Responder Version < 11.5\(4\)
CiscoEnterprise Chat And Email Version < 12.0\(1\)
CiscoFinesse Version < 12.6\(1\)
CiscoFog Director Version-
CiscoIdentity Services Engine Version < 2.4.0
CiscoIdentity Services Engine Version2.4.0 Update-
CiscoIntersight Virtual Appliance Version < 1.0.9-361
CiscoNetwork Assurance Engine Version < 6.0.2
CiscoNetwork Services Orchestrator Version < 5.3.5.1
CiscoNetwork Services Orchestrator Version >= 5.4 < 5.4.5.2
CiscoNetwork Services Orchestrator Version >= 5.5 < 5.5.4.1
CiscoNetwork Services Orchestrator Version >= 5.6 < 5.6.3.1
CiscoNexus Dashboard Version < 2.1.2
CiscoNexus Insights Version < 6.0.2
CiscoOptical Network Controller Version < 1.1.0
CiscoPaging Server Version < 14.4.1
CiscoPrime Service Catalog Version < 12.1
CiscoSd-wan Vmanage Version < 20.3.4.1
CiscoSd-wan Vmanage Version >= 20.4 < 20.4.2.1
CiscoSd-wan Vmanage Version >= 20.5 < 20.5.1.1
CiscoSd-wan Vmanage Version >= 20.6 < 20.6.2.1
CiscoSmart Phy Version < 3.2.1
CiscoUcs Central Version < 2.0\(1p\)
CiscoUcs Director Version < 6.8.2.0
CiscoUnified Communications Manager SwEdition- Version < 11.5\(1\)
CiscoUnified Communications Manager SwEditionsession_management Version < 11.5\(1\)
CiscoUnified Contact Center Enterprise Version < 11.6\(2\)
CiscoUnified Contact Center Express Version < 12.5\(1\)
CiscoUnified Intelligence Center Version < 12.6\(1\)
CiscoUnity Connection Version < 11.5\(1\)
CiscoVirtual Topology System Version < 2.6.7
CiscoVirtualized Infrastructure Manager Version >= 3.4.0 < 3.4.4
CiscoVirtualized Voice Browser Version < 12.5\(1\)
CiscoWan Automation Engine Version < 7.3.0.2
CiscoWebex Meetings Server Version < 3.0
CiscoWebex Meetings Server Version3.0 Update-
CiscoWebex Meetings Server Version3.0 Updatemaintenance_release1
CiscoWebex Meetings Server Version3.0 Updatemaintenance_release2
CiscoWebex Meetings Server Version3.0 Updatemaintenance_release3
CiscoWebex Meetings Server Version3.0 Updatemaintenance_release3 Edition-
CiscoWebex Meetings Server Version3.0 Updatemaintenance_release3_security_patch4
CiscoWebex Meetings Server Version3.0 Updatemaintenance_release3_security_patch5
CiscoWebex Meetings Server Version3.0 Updatemaintenance_release3_service_pack_2
CiscoWebex Meetings Server Version3.0 Updatemaintenance_release3_service_pack_3
CiscoWebex Meetings Server Version3.0 Updatemaintenance_release4
CiscoWebex Meetings Server Version4.0 Update-
CiscoWebex Meetings Server Version4.0 Updatemaintenance_release1
CiscoWebex Meetings Server Version4.0 Updatemaintenance_release2
CiscoWebex Meetings Server Version4.0 Updatemaintenance_release3
CiscoUnified Sip Proxy Version < 10.2.1v2
CiscoUnified Workforce Optimization Version < 11.5\(1\)
CiscoFxos Version6.2.3
   CiscoFirepower 1010 Version-
   CiscoFirepower 1120 Version-
   CiscoFirepower 1140 Version-
   CiscoFirepower 1150 Version-
   CiscoFirepower 2110 Version-
   CiscoFirepower 2120 Version-
   CiscoFirepower 2130 Version-
   CiscoFirepower 2140 Version-
   CiscoFirepower 4110 Version-
   CiscoFirepower 4112 Version-
   CiscoFirepower 4115 Version-
   CiscoFirepower 4120 Version-
   CiscoFirepower 4125 Version-
   CiscoFirepower 4140 Version-
   CiscoFirepower 4145 Version-
   CiscoFirepower 4150 Version-
   CiscoFirepower 9300 Version-
CiscoFxos Version6.3.0
   CiscoFirepower 1010 Version-
   CiscoFirepower 1120 Version-
   CiscoFirepower 1140 Version-
   CiscoFirepower 1150 Version-
   CiscoFirepower 2110 Version-
   CiscoFirepower 2120 Version-
   CiscoFirepower 2130 Version-
   CiscoFirepower 2140 Version-
   CiscoFirepower 4110 Version-
   CiscoFirepower 4112 Version-
   CiscoFirepower 4115 Version-
   CiscoFirepower 4120 Version-
   CiscoFirepower 4125 Version-
   CiscoFirepower 4140 Version-
   CiscoFirepower 4145 Version-
   CiscoFirepower 4150 Version-
   CiscoFirepower 9300 Version-
CiscoFxos Version6.4.0
   CiscoFirepower 1010 Version-
   CiscoFirepower 1120 Version-
   CiscoFirepower 1140 Version-
   CiscoFirepower 1150 Version-
   CiscoFirepower 2110 Version-
   CiscoFirepower 2120 Version-
   CiscoFirepower 2130 Version-
   CiscoFirepower 2140 Version-
   CiscoFirepower 4110 Version-
   CiscoFirepower 4112 Version-
   CiscoFirepower 4115 Version-
   CiscoFirepower 4120 Version-
   CiscoFirepower 4125 Version-
   CiscoFirepower 4140 Version-
   CiscoFirepower 4145 Version-
   CiscoFirepower 4150 Version-
   CiscoFirepower 9300 Version-
CiscoFxos Version6.5.0
   CiscoFirepower 1010 Version-
   CiscoFirepower 1120 Version-
   CiscoFirepower 1140 Version-
   CiscoFirepower 1150 Version-
   CiscoFirepower 2110 Version-
   CiscoFirepower 2120 Version-
   CiscoFirepower 2130 Version-
   CiscoFirepower 2140 Version-
   CiscoFirepower 4110 Version-
   CiscoFirepower 4112 Version-
   CiscoFirepower 4115 Version-
   CiscoFirepower 4120 Version-
   CiscoFirepower 4125 Version-
   CiscoFirepower 4140 Version-
   CiscoFirepower 4145 Version-
   CiscoFirepower 4150 Version-
   CiscoFirepower 9300 Version-
CiscoFxos Version6.6.0
   CiscoFirepower 1010 Version-
   CiscoFirepower 1120 Version-
   CiscoFirepower 1140 Version-
   CiscoFirepower 1150 Version-
   CiscoFirepower 2110 Version-
   CiscoFirepower 2120 Version-
   CiscoFirepower 2130 Version-
   CiscoFirepower 2140 Version-
   CiscoFirepower 4110 Version-
   CiscoFirepower 4112 Version-
   CiscoFirepower 4115 Version-
   CiscoFirepower 4120 Version-
   CiscoFirepower 4125 Version-
   CiscoFirepower 4140 Version-
   CiscoFirepower 4145 Version-
   CiscoFirepower 4150 Version-
   CiscoFirepower 9300 Version-
CiscoFxos Version6.7.0
   CiscoFirepower 1010 Version-
   CiscoFirepower 1120 Version-
   CiscoFirepower 1140 Version-
   CiscoFirepower 1150 Version-
   CiscoFirepower 2110 Version-
   CiscoFirepower 2120 Version-
   CiscoFirepower 2130 Version-
   CiscoFirepower 2140 Version-
   CiscoFirepower 4110 Version-
   CiscoFirepower 4112 Version-
   CiscoFirepower 4115 Version-
   CiscoFirepower 4120 Version-
   CiscoFirepower 4125 Version-
   CiscoFirepower 4140 Version-
   CiscoFirepower 4145 Version-
   CiscoFirepower 4150 Version-
   CiscoFirepower 9300 Version-
CiscoFxos Version7.0.0
   CiscoFirepower 1010 Version-
   CiscoFirepower 1120 Version-
   CiscoFirepower 1140 Version-
   CiscoFirepower 1150 Version-
   CiscoFirepower 2110 Version-
   CiscoFirepower 2120 Version-
   CiscoFirepower 2130 Version-
   CiscoFirepower 2140 Version-
   CiscoFirepower 4110 Version-
   CiscoFirepower 4112 Version-
   CiscoFirepower 4115 Version-
   CiscoFirepower 4120 Version-
   CiscoFirepower 4125 Version-
   CiscoFirepower 4140 Version-
   CiscoFirepower 4145 Version-
   CiscoFirepower 4150 Version-
   CiscoFirepower 9300 Version-
CiscoFxos Version7.1.0
   CiscoFirepower 1010 Version-
   CiscoFirepower 1120 Version-
   CiscoFirepower 1140 Version-
   CiscoFirepower 1150 Version-
   CiscoFirepower 2110 Version-
   CiscoFirepower 2120 Version-
   CiscoFirepower 2130 Version-
   CiscoFirepower 2140 Version-
   CiscoFirepower 4110 Version-
   CiscoFirepower 4112 Version-
   CiscoFirepower 4115 Version-
   CiscoFirepower 4120 Version-
   CiscoFirepower 4125 Version-
   CiscoFirepower 4140 Version-
   CiscoFirepower 4145 Version-
   CiscoFirepower 4150 Version-
   CiscoFirepower 9300 Version-
CiscoAutomated Subsea Tuning Version02.01.00
CiscoBroadworks Version-
CiscoConnected Analytics For Network Deployment Version008.000.000.000.004
CiscoCx Cloud Agent Version001.012
CiscoCyber Vision Version4.0.2
CiscoDna Center Version2.2.2.8
CiscoDna Spaces Version-
CiscoEmergency Responder Version11.5
CiscoFirepower Threat Defense Version6.2.3
CiscoFirepower Threat Defense Version6.3.0
CiscoFirepower Threat Defense Version6.4.0
CiscoFirepower Threat Defense Version6.5.0
CiscoFirepower Threat Defense Version6.6.0
CiscoFirepower Threat Defense Version6.7.0
CiscoFirepower Threat Defense Version7.0.0
CiscoFirepower Threat Defense Version7.1.0
CiscoIntersight Virtual Appliance Version1.0.9-343
CiscoPrime Service Catalog Version12.1
CiscoSd-wan Vmanage Version20.3
CiscoSd-wan Vmanage Version20.4
CiscoSd-wan Vmanage Version20.5
CiscoSd-wan Vmanage Version20.6
CiscoSd-wan Vmanage Version20.6.1
CiscoSd-wan Vmanage Version20.7
CiscoSd-wan Vmanage Version20.8
CiscoSmart Phy Version3.1.2
CiscoSmart Phy Version3.1.3
CiscoSmart Phy Version3.1.4
CiscoSmart Phy Version3.1.5
CiscoSmart Phy Version3.2.1
CiscoSmart Phy Version21.3
CiscoUcs Central Software Version2.0
CiscoUnity Connection Version11.5
CiscoVirtual Topology System Version2.6.6
CiscoWan Automation Engine Version7.1.3
CiscoWan Automation Engine Version7.2.1
CiscoWan Automation Engine Version7.2.2
CiscoWan Automation Engine Version7.2.3
CiscoWan Automation Engine Version7.3
CiscoWan Automation Engine Version7.4
CiscoWan Automation Engine Version7.5
CiscoWan Automation Engine Version7.6
CiscoWebex Meetings Server Version3.0
CiscoWebex Meetings Server Version4.0
SnowsoftwareSnow Commander Version < 8.10.0
SnowsoftwareVm Access Proxy Version < 3.6
BentleySynchro SwEditionpro Version >= 6.1 < 6.2.4.2
BentleySynchro 4d SwEditionpro Version < 6.4.3.2
PercussionRhythmyx Version <= 7.3.2
AppleXCode Version < 13.3

10.12.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Apache Log4j2 Remote Code Execution Vulnerability

Vulnerability

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Description

For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 94.36% 1
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

http://seclists.org/fulldisclosure/2022/Mar/23
Third Party Advisory
Mailing List
https://www.debian.org/security/2021/dsa-5020
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2022/Jul/11
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/2
Third Party Advisory
Exploit
Mailing List
http://www.openwall.com/lists/oss-security/2021/12/10/1
Third Party Advisory
Mailing List
Mitigation
http://www.openwall.com/lists/oss-security/2021/12/10/2
Third Party Advisory
Mailing List
Mitigation
https://twitter.com/kurtseifried/status/1469345530182455296
Third Party Advisory
Exploit
Broken Link
https://www.kb.cert.org/vuls/id/930724
Third Party Advisory
US Government Resource