peter bassill · operator
$ cve CVE-2021-44228 JSON

CVE-2021-44228 KEV EXPLOIT

10.0
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2021-12-24.

Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-20
On CISA KEVyes — remediate by 2021-12-24
Public exploityes
Published2021-12-10
Last modified2026-08-11

CISA KEV

NameApache Log4j2 Remote Code Execution Vulnerability
Added2021-12-10
Due2021-12-24
Vendor / productApache / Log4j2
Ransomware useknown

Affected (40)

VendorProduct
apachelog4j
siemens6bk1602-0aa12-0tp0
siemens6bk1602-0aa12-0tp0 firmware
siemens6bk1602-0aa22-0tp0
siemens6bk1602-0aa22-0tp0 firmware
siemens6bk1602-0aa32-0tp0
siemens6bk1602-0aa32-0tp0 firmware
siemens6bk1602-0aa42-0tp0
siemens6bk1602-0aa42-0tp0 firmware
siemens6bk1602-0aa52-0tp0
siemens6bk1602-0aa52-0tp0 firmware
siemenscapital
siemenscomos
siemensdesigo cc advanced reports
siemensdesigo cc info center
siemense-car operation center
siemensenergy engage
siemensenergyip
siemensenergyip prepay
siemensgma-manager
siemenshead-end system universal device integration system
siemensindustrial edge management
siemensindustrial edge management hub
siemenslogo\! soft comfort
siemensmendix
siemensmindsphere
siemensnavigator
siemensnx
siemensopcenter intelligence
siemensoperation scheduler
siemenssentron powermanager
siemenssiguard dsa
siemenssipass integrated
siemenssiveillance command
siemenssiveillance control pro
siemenssiveillance identity
siemenssiveillance vantage
siemenssiveillance viewpoint
siemenssppa-t3000 ses3000
siemenssppa-t3000 ses3000 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD