CVE-2021-44228, widely known as Log4Shell, is a critical vulnerability in the Apache Log4j2 library that allows unauthenticated remote code execution via insecure JNDI lookups, impacting a vast ecosystem of vendors including Cisco, VMware, and Apple. With a maximum CVSS score of 10.0, this flaw enables attackers to compromise systems over the network with low complexity and no required privileges by injecting malicious payloads into log messages. The vulnerability is actively exploited in the wild, appearing in the CISA Known Exploited Vulnerabilities catalog with confirmed use in ransomware campaigns, and has widely available public exploit code across major frameworks like Metasploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.7.0CPE matchmatch criteria | cpe:2.3:o:siemens:6bk1602-0aa12-0tp0_firmware:*:*:*:*:*:*:*:* | ||
< 2.7.0CPE matchmatch criteria | cpe:2.3:o:siemens:6bk1602-0aa22-0tp0_firmware:*:*:*:*:*:*:*:* | ||
< 2.7.0CPE matchmatch criteria | cpe:2.3:o:siemens:6bk1602-0aa32-0tp0_firmware:*:*:*:*:*:*:*:* | ||
< 2.7.0CPE matchmatch criteria | cpe:2.3:o:siemens:6bk1602-0aa42-0tp0_firmware:*:*:*:*:*:*:*:* | ||
< 2.7.0CPE matchmatch criteria | cpe:2.3:o:siemens:6bk1602-0aa52-0tp0_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products
Feb 1, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta On-Prem MFA Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Okta RADIUS Server Agent
Jan 26, 2022Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
Dec 22, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
Dec 21, 2021AS-2021-001: Log4Shell (Log4j 2)
Dec 16, 2021SPS Apache Log4j Vulnerability
Dec 16, 2021HBT Apache Log4j Vulnerability
Dec 16, 2021Apache Log4j Remote Code Execution Vulnerability
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Log4Shell Vulnerability (CVE-2021-4104 / CVE-2021-44228 / CVE-2021-45046 / CVE-2021-45105 )
Dec 14, 2021Niagara log4j NO IMPACT
Dec 13, 2021Niagara log4j NO IMPACT
Dec 13, 2021Niagara log4j NO IMPACT
Dec 13, 2021Niagara log4j NO IMPACT
Dec 13, 2021Niagara log4j NO IMPACT
Dec 13, 2021CVE-2021-44228: Apache Log4j Vulnerability
Dec 13, 2021NR21-04
Dec 13, 2021CVE-2021-44228: Apache Log4j Vulnerability
Dec 13, 2021Niagara log4j NO IMPACT
Dec 13, 2021Niagara log4j NO IMPACT
Dec 13, 2021log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value
Dec 10, 2021Remote code injection in Log4j
Dec 10, 2021NR21-03
Dec 10, 2021NR21-03
Dec 10, 2021