Networking-Forums.com

Professional Discussions => Vendor Advisories => Topic started by: Netwörkheäd on December 21, 2021, 06:06:30 PM

Title: Cisco Security Advisory - Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Post by: Netwörkheäd on December 21, 2021, 06:06:30 PM
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021

Critical Vulnerabilities in Apache Log4j Java Logging Library


On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed:



On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed:



On December 18, 2021, a vulnerability in the Apache Log4j component affecting versions 2.16 and earlier was disclosed:



For a description of these vulnerabilities, see the Apache Log4j Security Vulnerabilities page.


Cisco's Response to These Vulnerabilities


Cisco continues to assess all products and services for impact from both CVE-2021-44228 and CVE-2021-45046. To help detect exploitation of these vulnerabilities, Cisco has released Snort rules at the following location: Talos Rules 2021-12-21


Product fixes that are listed in this advisory will address both CVE-2021-44228 and CVE-2021-45046 unless otherwise noted.


Cisco is reviewing CVE-2021-45105 to determine what impact it may have on Cisco products and cloud offerings and will provide upgrades for affected products.


This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd



     
         
Security Impact Rating:  Critical
   
   
       
CVE: CVE-2021-44228,CVE-2021-45046
Source: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021 (https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Vulnerabilities%20in%20Apache%20Log4j%20Library%20Affecting%20Cisco%20Products:%20December%202021&vs_k=1)