CVE-2021-44228 KEV EXPLOIT
Patch first
On CISA KEV — known exploited in the wild, due 2021-12-24.
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 100% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | yes — remediate by 2021-12-24 |
| Public exploit | yes |
| Published | 2021-12-10 |
| Last modified | 2026-08-11 |
CISA KEV
| Name | Apache Log4j2 Remote Code Execution Vulnerability |
|---|---|
| Added | 2021-12-10 |
| Due | 2021-12-24 |
| Vendor / product | Apache / Log4j2 |
| Ransomware use | known |
Affected (40)
| Vendor | Product |
|---|---|
| apache | log4j |
| siemens | 6bk1602-0aa12-0tp0 |
| siemens | 6bk1602-0aa12-0tp0 firmware |
| siemens | 6bk1602-0aa22-0tp0 |
| siemens | 6bk1602-0aa22-0tp0 firmware |
| siemens | 6bk1602-0aa32-0tp0 |
| siemens | 6bk1602-0aa32-0tp0 firmware |
| siemens | 6bk1602-0aa42-0tp0 |
| siemens | 6bk1602-0aa42-0tp0 firmware |
| siemens | 6bk1602-0aa52-0tp0 |
| siemens | 6bk1602-0aa52-0tp0 firmware |
| siemens | capital |
| siemens | comos |
| siemens | desigo cc advanced reports |
| siemens | desigo cc info center |
| siemens | e-car operation center |
| siemens | energy engage |
| siemens | energyip |
| siemens | energyip prepay |
| siemens | gma-manager |
| siemens | head-end system universal device integration system |
| siemens | industrial edge management |
| siemens | industrial edge management hub |
| siemens | logo\! soft comfort |
| siemens | mendix |
| siemens | mindsphere |
| siemens | navigator |
| siemens | nx |
| siemens | opcenter intelligence |
| siemens | operation scheduler |
| siemens | sentron powermanager |
| siemens | siguard dsa |
| siemens | sipass integrated |
| siemens | siveillance command |
| siemens | siveillance control pro |
| siemens | siveillance identity |
| siemens | siveillance vantage |
| siemens | siveillance viewpoint |
| siemens | sppa-t3000 ses3000 |
| siemens | sppa-t3000 ses3000 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | AD Manager Plus 7122 - Remote Code Execution (RCE) | 2023-04-01 |
| exploit-db | Apache Log4j2 2.14.1 - Information Disclosure | 2021-12-14 |
| exploit-db | Apache Log4j 2 - Remote Code Execution (RCE) | 2021-12-14 |
References
- http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html
- http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html
- http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html
- http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html
- http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html
- http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html
- http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html
- http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html
- http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html
- http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2022/Dec/2
- http://seclists.org/fulldisclosure/2022/Jul/11
- http://seclists.org/fulldisclosure/2022/Mar/23
- http://www.openwall.com/lists/oss-security/2021/12/10/1
→ the Explorer · watch your stack · NVD