Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 100.0%; technical severity is CVSS 10.0.
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Who should care
- Teams operating Log4j, Log4j2, Xcode +140 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Log4j, Log4j2, Xcode +140 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Vendor remediation
Patch and remediation links
Use the vendor source below to confirm the correct fixed version, package or mitigation for your affected product.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- CWE
- CWE-20
- Affected versions
- Apache Log4j (Version: 2.0); Apache Log4j2; Apple Xcode (End Excluding: 13.3); Bentley Synchro (Start Including: 6.1, End Excluding: 6.2.4.2); Bentley Synchro 4d (End Excluding: 6.4.3.2); Cisco Advanced Malware Protection Virtual Private Cloud Appliance (End Excluding: 3.5.4); Cisco Automated Subsea Tuning (Version: 02.01.00); Cisco Broadworks (Version: -)
- Published
- 10 December 2021
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 100.0%
- Signal calculated at 88
External references
- Government advisory from www.cisa.gov
- Third-party advisory from packetstormsecurity.com
- Third-party advisory from packetstormsecurity.com
- Exploit information from packetstormsecurity.com
- Exploit information from packetstormsecurity.com
- Third-party advisory from packetstormsecurity.com
- Third-party advisory from packetstormsecurity.com
- Third-party advisory from packetstormsecurity.com
- Third-party advisory from packetstormsecurity.com
- Third-party advisory from packetstormsecurity.com
- Exploit information from packetstormsecurity.com
- Exploit information from packetstormsecurity.com