{
    "id": "CVE-2021-44228",
    "published": "2021-12-10 10:15:09",
    "last_modified": "2026-08-11 19:33:44",
    "cvss_score": "10.0",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "cwe": "CWE-20",
    "description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.",
    "epss_score": "0.99999",
    "epss_percentile": "1.00000",
    "kev": 1,
    "kev_due": "2021-12-24",
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:28:28",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2021-12-24."
    },
    "products": [
        {
            "vendor": "apache",
            "product": "log4j"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa12-0tp0"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa12-0tp0_firmware"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa22-0tp0"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa22-0tp0_firmware"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa32-0tp0"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa32-0tp0_firmware"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa42-0tp0"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa42-0tp0_firmware"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa52-0tp0"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa52-0tp0_firmware"
        },
        {
            "vendor": "siemens",
            "product": "capital"
        },
        {
            "vendor": "siemens",
            "product": "comos"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_advanced_reports"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_info_center"
        },
        {
            "vendor": "siemens",
            "product": "e-car_operation_center"
        },
        {
            "vendor": "siemens",
            "product": "energy_engage"
        },
        {
            "vendor": "siemens",
            "product": "energyip"
        },
        {
            "vendor": "siemens",
            "product": "energyip_prepay"
        },
        {
            "vendor": "siemens",
            "product": "gma-manager"
        },
        {
            "vendor": "siemens",
            "product": "head-end_system_universal_device_integration_system"
        },
        {
            "vendor": "siemens",
            "product": "industrial_edge_management"
        },
        {
            "vendor": "siemens",
            "product": "industrial_edge_management_hub"
        },
        {
            "vendor": "siemens",
            "product": "logo\\!_soft_comfort"
        },
        {
            "vendor": "siemens",
            "product": "mendix"
        },
        {
            "vendor": "siemens",
            "product": "mindsphere"
        },
        {
            "vendor": "siemens",
            "product": "navigator"
        },
        {
            "vendor": "siemens",
            "product": "nx"
        },
        {
            "vendor": "siemens",
            "product": "opcenter_intelligence"
        },
        {
            "vendor": "siemens",
            "product": "operation_scheduler"
        },
        {
            "vendor": "siemens",
            "product": "sentron_powermanager"
        },
        {
            "vendor": "siemens",
            "product": "siguard_dsa"
        },
        {
            "vendor": "siemens",
            "product": "sipass_integrated"
        },
        {
            "vendor": "siemens",
            "product": "siveillance_command"
        },
        {
            "vendor": "siemens",
            "product": "siveillance_control_pro"
        },
        {
            "vendor": "siemens",
            "product": "siveillance_identity"
        },
        {
            "vendor": "siemens",
            "product": "siveillance_vantage"
        },
        {
            "vendor": "siemens",
            "product": "siveillance_viewpoint"
        },
        {
            "vendor": "siemens",
            "product": "sppa-t3000_ses3000"
        },
        {
            "vendor": "siemens",
            "product": "sppa-t3000_ses3000_firmware"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2021-44228",
        "date_added": "2021-12-10",
        "due_date": "2021-12-24",
        "vendor": "Apache",
        "product": "Log4j2",
        "name": "Apache Log4j2 Remote Code Execution Vulnerability",
        "ransomware": 1
    },
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "51183",
            "title": "AD Manager Plus 7122 - Remote Code Execution (RCE)",
            "date": "2023-04-01",
            "url": "https://www.exploit-db.com/exploits/51183"
        },
        {
            "source": "exploit-db",
            "ref_id": "50590",
            "title": "Apache Log4j2 2.14.1 - Information Disclosure",
            "date": "2021-12-14",
            "url": "https://www.exploit-db.com/exploits/50590"
        },
        {
            "source": "exploit-db",
            "ref_id": "50592",
            "title": "Apache Log4j 2 - Remote Code Execution (RCE)",
            "date": "2021-12-14",
            "url": "https://www.exploit-db.com/exploits/50592"
        }
    ],
    "refs_list": [
        "http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
        "http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html",
        "http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html",
        "http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
        "http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html",
        "http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html",
        "http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html",
        "http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html",
        "http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html",
        "http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html",
        "http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html",
        "http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html",
        "http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html",
        "http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html",
        "http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html",
        "http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html",
        "http://seclists.org/fulldisclosure/2022/Dec/2",
        "http://seclists.org/fulldisclosure/2022/Jul/11",
        "http://seclists.org/fulldisclosure/2022/Mar/23",
        "http://www.openwall.com/lists/oss-security/2021/12/10/1",
        "http://www.openwall.com/lists/oss-security/2021/12/10/2",
        "http://www.openwall.com/lists/oss-security/2021/12/10/3",
        "http://www.openwall.com/lists/oss-security/2021/12/13/1",
        "http://www.openwall.com/lists/oss-security/2021/12/13/2",
        "http://www.openwall.com/lists/oss-security/2021/12/14/4"
    ]
}