CVE-2021-45046
Apache Log4j2 Deserialization of Untrusted Data Vulnerability - [Actively Exploited]
Description
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
INFO
Published Date :
Dec. 14, 2021, 7:15 p.m.
Last Modified :
Oct. 27, 2025, 5:35 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Apply updates per vendor instructions.
Known Detected May 01, 2023
https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046
Affected Products
The following products are affected by CVE-2021-45046
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 2.0 | MEDIUM | [email protected] | ||||
| CVSS 3.1 | CRITICAL | [email protected] | ||||
| CVSS 3.1 | CRITICAL | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
Solution
- Upgrade Apache Log4j to version 2.16.0 or later.
- Update affected packages to the latest versions.
- Apply vendor mitigations if upgrading is not possible.
Public PoC/Exploit Available at Github
CVE-2021-45046 has a 376 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2021-45046.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2021-45046 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2021-45046
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
PatchFlow CLI benchmark suites and reports
Shell
Terminal AI Pentesting Agent - Zero Trace, Zero Refusal, Dark Web Native. Runs 100% locally on phone or PC.
Python PowerShell Shell Batchfile
Ferramenta de linha de comando em Python 3 para consultar a API de busca de hosts do Shodan. Ela foi construída para uso em produção, com foco em resiliência, concorrência controlada e exibição completa dos dados retornados. É estritamente read-only — não realiza nenhum tipo de varredura ou exploração.
Python
COSMIC-AX PULSAR demonstration fixture (MERIDIAN-GS). Non-functional, manifest-only repo with intentionally outdated dependencies. No code, no secrets, no CI.
This is my Log4J Proof of Concept for my Software Security Class at Hochschule Bonn-Rhein-Sieg in SS2026
Dockerfile Java HTML
Damn Vulnerable Mobile — a self-contained, intentionally-vulnerable mobile backend lab with MASVS-mapped challenges, writeups, and a flag scoreboard. Training only.
appsec ctf education mobile-security owasp-masvs security-training vulnerable-app
Python Go TypeScript JavaScript Shell
Dependency vulnerability scanner over OSV.dev with CISA KEV actively-exploited flags. No API key.
apify appsec cisa-kev dependency-scanning mcp mcp-server model-context-protocol osv vulnerability-scanner
Vulnerability disclosure timeline builder with patch-window metrics
vulnerability-management timeline disclosure python cognis
Python Go JavaScript Rust
None
Python
None
Python Shell JavaScript HTML CSS PHP Smarty Go Template Less PowerShell
None
Dockerfile Makefile Go Go Template HTML TypeScript JavaScript
Validate OTA update packages end-to-end: signature chains, rollback protection, anti-downgrade counters, and delta-patch integrity.
cognis-digital cognis-neural-suite automation cli embedded firmware iot mcp-server ot-security python self-hosted otaverify security-tools ai cognis llm machine-learning embedded-security firmware-security ota-updates
Dockerfile Python Shell Go JavaScript Rust HCL PowerShell
Generate a CycloneDX SBOM directly from an unpacked firmware root filesystem and flag components with known CVEs and EOL kernels.
cognis-digital cognis-neural-suite automation cli embedded firmware iot mcp-server ot-security python sbomb self-hosted security vulnerability-scanner cloud cognis developer-tools devtools sbom
Dockerfile Python Shell Go JavaScript Rust HCL PowerShell
Dockerfile linter with image-size and CVE advisories
cognis-digital cognis-neural-suite automation cli developer-tools devops mcp-server productivity python self-hosted shipcheck cloud-security maritime security vulnerability-scanner aerospace cognis defense defense-tech
Dockerfile Python Shell Go JavaScript Rust HCL PowerShell
Third-party / vendor risk questionnaires with SBOM cross-ref
cognis-digital cognis-neural-suite automation cli compliance grc iso27001 mcp-server python self-hosted soc2 vendorvet security vulnerability-scanner cognis govtech sbom
Dockerfile Python Shell Go JavaScript Rust HCL PowerShell
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2021-45046 vulnerability anywhere in the article.
-
Daily CyberSecurity
Log4j’s “Silent” Security Gap: New Advisories Warn of Data Loss and TLS Bypasses
The Apache Log4j 2 ecosystem is facing a fresh wave of security concerns as four new vulnerabilities have been disclosed, highlighting critical flaws in how the library handles data sanitization and i ... Read more
-
cybereason.com
CVE-2025-32433: Unauthenticated RCE Vulnerability in Erlang/OTP’s SSH Implementation
Key Takeaways A critical vulnerability has been discovered in Erlang/OTP, tracked as CVE-2025-32433, and has a CVSS score of 10 (critical). This critical remote code execution (RCE) vulnerability aff ... Read more
-
Google Cloud
Ransomware Rebounds: Extortion Threat Surges in 2023, Attackers Rely on Publicly Available and Legitimate Tools
Written by: Bavi Sadayappan, Zach Riddle, Jordan Nuce, Joshua Shilko, Jeremy Kennelly A version of this blog post was published to the Mandiant Advantage portal on April 18, 2024. Executive Summary In ... Read more
-
huntress.com
VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress
On January 5, the UK’s National Health Service (NHS) alerted that hackers were actively targeting Log4Shell vulnerabilities in VMware Horizon servers in an effort to establish persistent access via we ... Read more
-
curatedintel.org
Nightmare Before Christmas - Curated Intel's Response To Log4Shell
Written by @BushidoToken, @TrevorGiffen | Edited by @SteveD3On late Thursday, 9 December, security researchers warned of a critical vulnerability with wide ramifications. With a CVSS score of 10.0 (Cr ... Read more
The following table lists the changes that have been made to the
CVE-2021-45046 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Modified Analysis by [email protected]
Oct. 27, 2025
Action Type Old Value New Value Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046 Types: US Government Resource -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Oct. 22, 2025
Action Type Old Value New Value Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Oct. 21, 2025
Action Type Old Value New Value Removed Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Oct. 21, 2025
Action Type Old Value New Value Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45046 -
Modified Analysis by [email protected]
Mar. 12, 2025
Action Type Old Value New Value Changed CPE Configuration AND OR *cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:* OR cpe:2.3:h:siemens:sppa-t3000_ses3000:-:*:*:*:*:*:*:* AND OR *cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:* OR cpe:2.3:h:siemens:sppa-t3000_ses3000:-:*:*:*:*:*:*:* Changed CPE Configuration AND OR *cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:* OR cpe:2.3:h:siemens:sppa-t3000_ses3000:-:*:*:*:*:*:*:* AND OR *cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:* OR cpe:2.3:h:siemens:sppa-t3000_ses3000:-:*:*:*:*:*:*:* -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Feb. 04, 2025
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Nov. 21, 2024
Action Type Old Value New Value Added Reference http://www.openwall.com/lists/oss-security/2021/12/14/4 Added Reference http://www.openwall.com/lists/oss-security/2021/12/15/3 Added Reference http://www.openwall.com/lists/oss-security/2021/12/18/1 Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf Added Reference https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/ Added Reference https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/ Added Reference https://logging.apache.org/log4j/2.x/security.html Added Reference https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032 Added Reference https://security.gentoo.org/glsa/202310-16 Added Reference https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Added Reference https://www.cve.org/CVERecord?id=CVE-2021-44228 Added Reference https://www.debian.org/security/2021/dsa-5022 Added Reference https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html Added Reference https://www.kb.cert.org/vuls/id/930724 Added Reference https://www.oracle.com/security-alerts/alert-cve-2021-44228.html Added Reference https://www.oracle.com/security-alerts/cpuapr2022.html Added Reference https://www.oracle.com/security-alerts/cpujan2022.html Added Reference https://www.oracle.com/security-alerts/cpujul2022.html -
CPE Deprecation Remap by [email protected]
Oct. 31, 2024
Action Type Old Value New Value Changed CPE Configuration OR *cpe:2.3:a:intel:computer_vision_annotation_tool:-:*:*:*:*:*:*:* OR *cpe:2.3:a:cvat:computer_vision_annotation_tool:-:*:*:*:*:*:*:* -
Modified Analysis by [email protected]
Jun. 27, 2024
Action Type Old Value New Value Changed Reference Type https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/ No Types Assigned https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/ Mailing List, Release Notes Changed Reference Type https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/ No Types Assigned https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/ Mailing List, Release Notes Changed Reference Type https://security.gentoo.org/glsa/202310-16 No Types Assigned https://security.gentoo.org/glsa/202310-16 Third Party Advisory Changed CPE Configuration AND OR cpe:2.3:h:siemens:sppa-t3000_ses3000:-:*:*:*:*:*:*:* OR *cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:* AND OR *cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:* OR cpe:2.3:h:siemens:sppa-t3000_ses3000:-:*:*:*:*:*:*:* -
CVE Modified by [email protected]
May. 14, 2024
Action Type Old Value New Value -
CVE Modified by [email protected]
Oct. 26, 2023
Action Type Old Value New Value Added Reference https://security.gentoo.org/glsa/202310-16 [No Types Assigned] -
CVE Modified by [email protected]
Jun. 27, 2023
Action Type Old Value New Value Removed Reference https://lists.fedoraproject.org/archives/list/[email protected]/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/ [Mailing List, Third Party Advisory] Removed Reference https://lists.fedoraproject.org/archives/list/[email protected]/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/ [Mailing List, Third Party Advisory] Added Reference https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/ [No Types Assigned] Added Reference https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/ [No Types Assigned] Removed CWE Apache Software Foundation CWE-502 Added CWE Apache Software Foundation CWE-917 Removed CWE Reason CWE-502 / More specific CWE option available -
Reanalysis by [email protected]
Jun. 26, 2023
Action Type Old Value New Value Removed CWE NIST CWE-502 Added CWE NIST CWE-917 -
Modified Analysis by [email protected]
Oct. 06, 2022
Action Type Old Value New Value Changed Reference Type https://www.oracle.com/security-alerts/cpuapr2022.html No Types Assigned https://www.oracle.com/security-alerts/cpuapr2022.html Third Party Advisory Changed Reference Type https://www.oracle.com/security-alerts/cpujul2022.html No Types Assigned https://www.oracle.com/security-alerts/cpujul2022.html Third Party Advisory -
CVE Modified by [email protected]
Jul. 25, 2022
Action Type Old Value New Value Added Reference https://www.oracle.com/security-alerts/cpujul2022.html [No Types Assigned] -
CVE Modified by [email protected]
Apr. 20, 2022
Action Type Old Value New Value Added Reference https://www.oracle.com/security-alerts/cpuapr2022.html [No Types Assigned] -
Modified Analysis by [email protected]
Feb. 19, 2022
Action Type Old Value New Value Changed Reference Type https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf No Types Assigned https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf Third Party Advisory Changed Reference Type https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf No Types Assigned https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf Third Party Advisory Changed Reference Type https://lists.fedoraproject.org/archives/list/[email protected]/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/ No Types Assigned https://lists.fedoraproject.org/archives/list/[email protected]/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/ Mailing List, Third Party Advisory Changed Reference Type https://lists.fedoraproject.org/archives/list/[email protected]/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/ No Types Assigned https://lists.fedoraproject.org/archives/list/[email protected]/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/ Mailing List, Third Party Advisory Changed Reference Type https://www.oracle.com/security-alerts/cpujan2022.html No Types Assigned https://www.oracle.com/security-alerts/cpujan2022.html Patch, Third Party Advisory Changed CPE Configuration OR *cpe:2.3:a:siemens:captial:*:*:*:*:*:*:*:* versions up to (excluding) 2019.1 *cpe:2.3:a:siemens:captial:2019.1:-:*:*:*:*:*:* *cpe:2.3:a:siemens:captial:2019.1:sp1912:*:*:*:*:*:* *cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_info_center:5.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_info_center:5.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:e-car_operation_center:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:energy_engage:3.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:8.5:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:8.6:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:8.7:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:9.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip_prepay:3.7:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip_prepay:3.8:*:*:*:*:*:*:* *cpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:* versions up to (excluding) 8.6.2j-398 *cpe:2.3:a:siemens:head-end_system_universal_device_integration_system:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:industrial_edge_management:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:industrial_edge_management_hub:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:logo\!_soft_comfort:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:mendix:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:mindsphere:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-11 *cpe:2.3:a:siemens:navigator:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:nx:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:opcenter_intelligence:*:*:*:*:*:*:*:* versions up to (including) 3.2 *cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:* versions up to (including) 1.1.3 *cpe:2.3:a:siemens:sentron_powermanager:4.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sentron_powermanager:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siguard_dsa:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siguard_dsa:4.3:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siguard_dsa:4.4:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:* versions up to (including) 4.16.2.1 *cpe:2.3:a:siemens:siveillance_control_pro:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_vantage:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_viewpoint:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_cam_pro:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_harness_design:*:*:*:*:*:*:*:* versions up to (excluding) 2020 *cpe:2.3:a:siemens:solid_edge_harness_design:2020:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_harness_design:2020:-:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_harness_design:2020:sp2002:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:* versions up to (excluding) 4.70 *cpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:* versions up to (excluding) 2.30 *cpe:2.3:a:siemens:spectrum_power_7:2.30:*:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:2.30:-:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:2.30:sp2:*:*:*:*:*:* *cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:*:*:*:*:*:*:*:* versions up to (excluding) 2019.1 *cpe:2.3:a:siemens:vesys:2019.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:2019.1:-:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:2019.1:sp1912:*:*:*:*:*:* *cpe:2.3:a:siemens:xpedition_enterprise:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:xpedition_package_integrator:-:*:*:*:*:*:*:* OR *cpe:2.3:a:siemens:captial:*:*:*:*:*:*:*:* versions up to (excluding) 2019.1 *cpe:2.3:a:siemens:captial:2019.1:-:*:*:*:*:*:* *cpe:2.3:a:siemens:captial:2019.1:sp1912:*:*:*:*:*:* *cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_info_center:5.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_info_center:5.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:e-car_operation_center:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:energy_engage:3.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:8.5:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:8.6:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:8.7:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:9.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip_prepay:3.7:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip_prepay:3.8:*:*:*:*:*:*:* *cpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:* versions up to (excluding) 8.6.2j-398 *cpe:2.3:a:siemens:head-end_system_universal_device_integration_system:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:industrial_edge_management:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:industrial_edge_management_hub:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:logo\!_soft_comfort:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:mendix:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:mindsphere:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-11 *cpe:2.3:a:siemens:navigator:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:nx:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:opcenter_intelligence:*:*:*:*:*:*:*:* versions up to (including) 3.2 *cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:* versions up to (including) 1.1.3 *cpe:2.3:a:siemens:sentron_powermanager:4.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sentron_powermanager:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siguard_dsa:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siguard_dsa:4.3:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siguard_dsa:4.4:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:* versions up to (including) 4.16.2.1 *cpe:2.3:a:siemens:siveillance_control_pro:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_vantage:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_viewpoint:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_cam_pro:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_harness_design:*:*:*:*:*:*:*:* versions up to (excluding) 2020 *cpe:2.3:a:siemens:solid_edge_harness_design:2020:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_harness_design:2020:-:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_harness_design:2020:sp2002:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:* versions up to (excluding) 4.70 *cpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:* versions up to (excluding) 2.30 *cpe:2.3:a:siemens:spectrum_power_7:2.30:*:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:2.30:-:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:2.30:sp2:*:*:*:*:*:* *cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:tracealertserverplus:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:*:*:*:*:*:*:*:* versions up to (excluding) 2019.1 *cpe:2.3:a:siemens:vesys:2019.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:2019.1:-:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:2019.1:sp1912:*:*:*:*:*:* *cpe:2.3:a:siemens:xpedition_enterprise:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:xpedition_package_integrator:-:*:*:*:*:*:*:* Added CPE Configuration OR *cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* *cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:o:siemens:6bk1602-0aa12-0tp0_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.7.0 OR cpe:2.3:h:siemens:6bk1602-0aa12-0tp0:-:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:o:siemens:6bk1602-0aa22-0tp0_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.7.0 OR cpe:2.3:h:siemens:6bk1602-0aa22-0tp0:-:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:o:siemens:6bk1602-0aa32-0tp0_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.7.0 OR cpe:2.3:h:siemens:6bk1602-0aa32-0tp0:-:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:o:siemens:6bk1602-0aa42-0tp0_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.7.0 OR cpe:2.3:h:siemens:6bk1602-0aa42-0tp0:-:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:o:siemens:6bk1602-0aa52-0tp0_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.7.0 OR cpe:2.3:h:siemens:6bk1602-0aa52-0tp0:-:*:*:*:*:*:*:* -
CVE Modified by [email protected]
Feb. 07, 2022
Action Type Old Value New Value Added Reference https://www.oracle.com/security-alerts/cpujan2022.html [No Types Assigned] -
CVE Modified by [email protected]
Dec. 27, 2021
Action Type Old Value New Value Added Reference https://lists.fedoraproject.org/archives/list/[email protected]/message/EOKPQGV24RRBBI4TBZUDQMM4MEH7MXCY/ [No Types Assigned] Added Reference https://lists.fedoraproject.org/archives/list/[email protected]/message/SIG7FZULMNK2XF6FZRU4VWYDQXNMUGAJ/ [No Types Assigned] -
CVE Modified by [email protected]
Dec. 22, 2021
Action Type Old Value New Value Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf [No Types Assigned] -
CVE Modified by [email protected]
Dec. 21, 2021
Action Type Old Value New Value Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf [No Types Assigned] -
Modified Analysis by [email protected]
Dec. 20, 2021
Action Type Old Value New Value Removed CVSS V2 NIST (AV:N/AC:H/Au:N/C:N/I:N/A:P) Added CVSS V2 NIST (AV:N/AC:H/Au:N/C:P/I:P/A:P) Removed CVSS V3.1 NIST AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Added CVSS V3.1 NIST AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Changed Reference Type http://www.openwall.com/lists/oss-security/2021/12/18/1 No Types Assigned http://www.openwall.com/lists/oss-security/2021/12/18/1 Mailing List, Third Party Advisory Changed Reference Type https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032 No Types Assigned https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032 Third Party Advisory Changed Reference Type https://www.debian.org/security/2021/dsa-5022 No Types Assigned https://www.debian.org/security/2021/dsa-5022 Third Party Advisory Changed Reference Type https://www.oracle.com/security-alerts/alert-cve-2021-44228.html No Types Assigned https://www.oracle.com/security-alerts/alert-cve-2021-44228.html Third Party Advisory Added CPE Configuration OR *cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* *cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Added CPE Configuration OR *cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.12 -
CVE Modified by [email protected]
Dec. 20, 2021
Action Type Old Value New Value Changed Description It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a denial of service (DOS) attack. Log4j 2.15.0 makes a best-effort attempt to restrict JNDI LDAP lookups to localhost by default. Log4j 2.16.0 fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default. It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default. -
CVE Modified by [email protected]
Dec. 18, 2021
Action Type Old Value New Value Added Reference http://www.openwall.com/lists/oss-security/2021/12/18/1 [No Types Assigned] -
CVE Modified by [email protected]
Dec. 18, 2021
Action Type Old Value New Value Added Reference https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032 [No Types Assigned] -
CVE Modified by [email protected]
Dec. 17, 2021
Action Type Old Value New Value Added Reference https://www.oracle.com/security-alerts/alert-cve-2021-44228.html [No Types Assigned] -
CVE Modified by [email protected]
Dec. 16, 2021
Action Type Old Value New Value Added Reference https://www.debian.org/security/2021/dsa-5022 [No Types Assigned] -
Modified Analysis by [email protected]
Dec. 16, 2021
Action Type Old Value New Value Changed Reference Type http://www.openwall.com/lists/oss-security/2021/12/15/3 No Types Assigned http://www.openwall.com/lists/oss-security/2021/12/15/3 Mailing List, Third Party Advisory Changed Reference Type https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf No Types Assigned https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf Third Party Advisory Changed Reference Type https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf No Types Assigned https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf Third Party Advisory Changed Reference Type https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd No Types Assigned https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory Changed Reference Type https://www.kb.cert.org/vuls/id/930724 No Types Assigned https://www.kb.cert.org/vuls/id/930724 Third Party Advisory, US Government Resource Removed CPE Configuration OR *cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* *cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* *cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Removed CPE Configuration OR *cpe:2.3:a:arubanetworks:silver_peak_orchestrator:-:*:*:*:*:*:*:* Removed CPE Configuration OR *cpe:2.3:a:siemens:capital:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:cosmos:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:4.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:4.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:5.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:5.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_info_center:5.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_info_center:5.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:e-car_operating_center:*:*:*:*:cloud:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:energyip_prepay:3.7:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip_prepay:3.8:*:*:*:*:*:*:* *cpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:* versions from (including) 8.6.2j-398 *cpe:2.3:a:siemens:head-end_system_universal_device_integration_system:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:industrial_edge_management:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:simatic_wincc:7.4:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:* versions up to (including) 4.16.2.1 *cpe:2.3:a:siemens:siveillance_control:*:*:*:*:pro:*:*:* versions up to (excluding) 2.1 *cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_vantage:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_wiring_harness_design:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:* versions up to (excluding) 4.70 *cpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:teamcenter_suite:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:xpedition_enterprise_data_management:*:*:*:*:*:*:*:* versions from (including) 2.6 up to (including) 2.10 *cpe:2.3:a:siemens:xpedition_package_integrator:*:*:*:*:*:*:*:* versions from (including) 2.6 up to (including) 2.10 *cpe:2.3:o:siemens:dynamic_security_assessment:4.2:*:*:*:*:*:*:* *cpe:2.3:o:siemens:dynamic_security_assessment:4.3:*:*:*:*:*:*:* *cpe:2.3:o:siemens:dynamic_security_assessment:4.4:*:*:*:*:*:*:* *cpe:2.3:o:siemens:industrial_edge_management:-:*:*:*:*:*:*:* *cpe:2.3:o:siemens:industrial_edge_manangement_hub:-:*:*:*:*:*:*:* *cpe:2.3:o:siemens:logo\!_soft_comfort:-:*:*:*:*:*:*:* *cpe:2.3:o:siemens:mendix:-:*:*:*:*:*:*:* *cpe:2.3:o:siemens:mindsphere:*:*:*:*:cloud:*:*:* versions up to (excluding) 2021-12-11 *cpe:2.3:o:siemens:nx:-:*:*:*:*:*:*:* *cpe:2.3:o:siemens:opcenter_intelligence:*:*:*:*:*:*:*:* versions from (including) 3.2 *cpe:2.3:o:siemens:operation_scheduler:*:*:*:*:*:*:*:* versions from (including) 1.1.3 Changed CPE Configuration OR *cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:2.0:rc2:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* versions from (including) 2.0.1 up to (including) 2.12.1 *cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* versions from (including) 2.13.0 up to (excluding) 2.15.0 OR *cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:2.0:rc2:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* versions from (including) 2.0.1 up to (excluding) 2.12.2 *cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* versions from (including) 2.13.0 up to (excluding) 2.16.0 Changed CPE Configuration OR *cpe:2.3:a:intel:audio_development_kit:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:datacenter_manager:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:oneapi:-:*:*:*:*:eclipse:*:* *cpe:2.3:a:intel:secure_device_onboard:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:system_debugger:-:*:*:*:*:*:*:* OR *cpe:2.3:a:intel:audio_development_kit:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:computer_vision_annotation_tool:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:datacenter_manager:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:genomics_kernel_library:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:oneapi:-:*:*:*:*:eclipse:*:* *cpe:2.3:a:intel:secure_device_onboard:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:sensor_solution_firmware_development_kit:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:system_debugger:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:system_studio:-:*:*:*:*:*:*:* Changed CPE Configuration OR *cpe:2.3:a:netapp:brocade_san_navigator:-:*:*:*:*:*:*:* *cpe:2.3:a:netapp:cloud_insights_acquisition_unit:-:*:*:*:*:*:*:* *cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:* *cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:* *cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* *cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:* *cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:vmware_vsphere:*:* AND OR *cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:* OR cpe:2.3:h:siemens:sppa-t3000_ses3000:-:*:*:*:*:*:*:* Changed CPE Configuration OR *cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* OR *cpe:2.3:a:siemens:captial:*:*:*:*:*:*:*:* versions up to (excluding) 2019.1 *cpe:2.3:a:siemens:captial:2019.1:-:*:*:*:*:*:* *cpe:2.3:a:siemens:captial:2019.1:sp1912:*:*:*:*:*:* *cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_info_center:5.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_cc_info_center:5.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:e-car_operation_center:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:energy_engage:3.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:8.5:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:8.6:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:8.7:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip:9.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip_prepay:3.7:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip_prepay:3.8:*:*:*:*:*:*:* *cpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:* versions up to (excluding) 8.6.2j-398 *cpe:2.3:a:siemens:head-end_system_universal_device_integration_system:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:industrial_edge_management:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:industrial_edge_management_hub:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:logo\!_soft_comfort:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:mendix:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:mindsphere:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-11 *cpe:2.3:a:siemens:navigator:*:*:*:*:*:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:nx:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:opcenter_intelligence:*:*:*:*:*:*:*:* versions up to (including) 3.2 *cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:* versions up to (including) 1.1.3 *cpe:2.3:a:siemens:sentron_powermanager:4.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sentron_powermanager:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siguard_dsa:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siguard_dsa:4.3:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siguard_dsa:4.4:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:* versions up to (including) 4.16.2.1 *cpe:2.3:a:siemens:siveillance_control_pro:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_vantage:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_viewpoint:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_cam_pro:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_harness_design:*:*:*:*:*:*:*:* versions up to (excluding) 2020 *cpe:2.3:a:siemens:solid_edge_harness_design:2020:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_harness_design:2020:-:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_harness_design:2020:sp2002:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:* versions up to (excluding) 4.70 *cpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:* versions up to (excluding) 2.30 *cpe:2.3:a:siemens:spectrum_power_7:2.30:*:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:2.30:-:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:2.30:sp2:*:*:*:*:*:* *cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:*:*:*:*:*:*:*:* versions up to (excluding) 2019.1 *cpe:2.3:a:siemens:vesys:2019.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:2019.1:-:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:2019.1:sp1912:*:*:*:*:*:* *cpe:2.3:a:siemens:xpedition_enterprise:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:xpedition_package_integrator:-:*:*:*:*:*:*:* -
CVE Modified by [email protected]
Dec. 16, 2021
Action Type Old Value New Value Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf [No Types Assigned] -
CVE Modified by [email protected]
Dec. 16, 2021
Action Type Old Value New Value Added Reference https://www.kb.cert.org/vuls/id/930724 [No Types Assigned] -
CVE Modified by [email protected]
Dec. 16, 2021
Action Type Old Value New Value Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf [No Types Assigned] -
CVE Modified by [email protected]
Dec. 15, 2021
Action Type Old Value New Value Added Reference http://www.openwall.com/lists/oss-security/2021/12/15/3 [No Types Assigned] -
CVE Modified by [email protected]
Dec. 15, 2021
Action Type Old Value New Value Added Reference https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd [No Types Assigned] -
CVE Modified by [email protected]
Dec. 15, 2021
Action Type Old Value New Value Changed Description It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a denial of service (DOS) attack. Log4j 2.15.0 makes a best-effort attempt to restrict JNDI LDAP lookups to localhost by default. Log4j 2.16.0 fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default. It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a denial of service (DOS) attack. Log4j 2.15.0 makes a best-effort attempt to restrict JNDI LDAP lookups to localhost by default. Log4j 2.16.0 fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default. Removed Reference http://www.openwall.com/lists/oss-security/2021/12/15/1 [No Types Assigned] Removed Reference https://security.netapp.com/advisory/ntap-20211215-0001/ [No Types Assigned] -
CVE Modified by [email protected]
Dec. 15, 2021
Action Type Old Value New Value Changed Description It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a denial of service (DOS) attack. Log4j 2.15.0 restricts JNDI LDAP lookups to localhost by default. Note that previous mitigations involving configuration such as to set the system property `log4j2.noFormatMsgLookup` to `true` do NOT mitigate this specific vulnerability. Log4j 2.16.0 fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default. This issue can be mitigated in prior releases (<2.16.0) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a denial of service (DOS) attack. Log4j 2.15.0 makes a best-effort attempt to restrict JNDI LDAP lookups to localhost by default. Log4j 2.16.0 fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default. Added Reference http://www.openwall.com/lists/oss-security/2021/12/15/1 [No Types Assigned] Added Reference https://security.netapp.com/advisory/ntap-20211215-0001/ [No Types Assigned] -
Initial Analysis by [email protected]
Dec. 15, 2021
Action Type Old Value New Value Added CVSS V2 NIST (AV:N/AC:H/Au:N/C:N/I:N/A:P) Added CVSS V3.1 NIST AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Changed Reference Type http://www.openwall.com/lists/oss-security/2021/12/14/4 No Types Assigned http://www.openwall.com/lists/oss-security/2021/12/14/4 Mailing List, Mitigation, Third Party Advisory Changed Reference Type https://logging.apache.org/log4j/2.x/security.html No Types Assigned https://logging.apache.org/log4j/2.x/security.html Mitigation, Release Notes, Vendor Advisory Changed Reference Type https://www.cve.org/CVERecord?id=CVE-2021-44228 No Types Assigned https://www.cve.org/CVERecord?id=CVE-2021-44228 Not Applicable Changed Reference Type https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html No Types Assigned https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html Third Party Advisory Added CWE NIST CWE-502 Added CPE Configuration OR *cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:2.0:rc2:*:*:*:*:*:* *cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* versions from (including) 2.0.1 up to (including) 2.12.1 *cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* versions from (including) 2.13.0 up to (excluding) 2.15.0 Added CPE Configuration OR *cpe:2.3:a:intel:audio_development_kit:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:datacenter_manager:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:oneapi:-:*:*:*:*:eclipse:*:* *cpe:2.3:a:intel:secure_device_onboard:-:*:*:*:*:*:*:* *cpe:2.3:a:intel:system_debugger:-:*:*:*:*:*:*:* Added CPE Configuration OR *cpe:2.3:a:netapp:brocade_san_navigator:-:*:*:*:*:*:*:* *cpe:2.3:a:netapp:cloud_insights_acquisition_unit:-:*:*:*:*:*:*:* *cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:* *cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:* *cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* *cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:* *cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:vmware_vsphere:*:* Added CPE Configuration OR *cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* Added CPE Configuration OR *cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* *cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* *cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Added CPE Configuration OR *cpe:2.3:a:arubanetworks:silver_peak_orchestrator:-:*:*:*:*:*:*:* Added CPE Configuration OR *cpe:2.3:a:siemens:capital:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:cosmos:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:*:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:4.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:4.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:4.2:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:5.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:5.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_info_center:5.0:*:*:*:*:*:*:* *cpe:2.3:a:siemens:desigo_consumption_control_info_center:5.1:*:*:*:*:*:*:* *cpe:2.3:a:siemens:e-car_operating_center:*:*:*:*:cloud:*:*:* versions up to (excluding) 2021-12-13 *cpe:2.3:a:siemens:energyip_prepay:3.7:*:*:*:*:*:*:* *cpe:2.3:a:siemens:energyip_prepay:3.8:*:*:*:*:*:*:* *cpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:* versions from (including) 8.6.2j-398 *cpe:2.3:a:siemens:head-end_system_universal_device_integration_system:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:industrial_edge_management:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:simatic_wincc:7.4:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:* *cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:* versions up to (including) 4.16.2.1 *cpe:2.3:a:siemens:siveillance_control:*:*:*:*:pro:*:*:* versions up to (excluding) 2.1 *cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:* *cpe:2.3:a:siemens:siveillance_vantage:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:solid_edge_wiring_harness_design:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:* versions up to (excluding) 4.70 *cpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:* *cpe:2.3:a:siemens:spectrum_power_7:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:teamcenter_suite:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:vesys:-:*:*:*:*:*:*:* *cpe:2.3:a:siemens:xpedition_enterprise_data_management:*:*:*:*:*:*:*:* versions from (including) 2.6 up to (including) 2.10 *cpe:2.3:a:siemens:xpedition_package_integrator:*:*:*:*:*:*:*:* versions from (including) 2.6 up to (including) 2.10 *cpe:2.3:o:siemens:dynamic_security_assessment:4.2:*:*:*:*:*:*:* *cpe:2.3:o:siemens:dynamic_security_assessment:4.3:*:*:*:*:*:*:* *cpe:2.3:o:siemens:dynamic_security_assessment:4.4:*:*:*:*:*:*:* *cpe:2.3:o:siemens:industrial_edge_management:-:*:*:*:*:*:*:* *cpe:2.3:o:siemens:industrial_edge_manangement_hub:-:*:*:*:*:*:*:* *cpe:2.3:o:siemens:logo\!_soft_comfort:-:*:*:*:*:*:*:* *cpe:2.3:o:siemens:mendix:-:*:*:*:*:*:*:* *cpe:2.3:o:siemens:mindsphere:*:*:*:*:cloud:*:*:* versions up to (excluding) 2021-12-11 *cpe:2.3:o:siemens:nx:-:*:*:*:*:*:*:* *cpe:2.3:o:siemens:opcenter_intelligence:*:*:*:*:*:*:*:* versions from (including) 3.2 *cpe:2.3:o:siemens:operation_scheduler:*:*:*:*:*:*:*:* versions from (including) 1.1.3 -
CVE Modified by [email protected]
Dec. 15, 2021
Action Type Old Value New Value Added Reference https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html [No Types Assigned]