Pilz Hardware And Software Not Affected By “Log4Shell” Vulnerability In Software Library Log4j

DCS PILZ Log4Shell Vulnerability 1 400

December 17, 2021

 

Dear Madam or Sir,

 

On December 10th, 2021, the BSI (the German Federal Office for Information Security) published a cyber security alert on the so-called “Log4Shell” vulnerability in the software library Log4j. Log4j is used in many Java applications.

From the BSI alert:

“An IT security vendor blog [LUN2021] reports on vulnerability CVE-2021-44228 [MIT2021] in log4j versions 2.0 through 2.14.1, which may allow attackers to execute their own program code on the target system and thus compromise the server.”

 

Further information is available at:

 

Pilz’s analysis revealed the following:

  • ••Pilz hardware components do not use Java and thus no log4j. Therefore, these components are not affected.
  • ••Pilz Software products partially use log4j versions 2.0 to 2.14.1 (current vulnerability CVE-2021-44228). Analyses to date have shown that it is highly unlikely that the vulnerability can be exploited. If, contrary to expectations, there is a risk, we will publish a security advisory.
  • ••In some Pilz Software products, log4j version 1.2.x is used. The exploitation of the vulnerability in this version (CVE 2021-4104) requires, among other things, a specific configuration. However, this configuration is not used in Pilz Software products.

 

We hope this information is helpful to you. If you have any further questions, please contact our technical support:support@pilz.com.

With best regards

Pilz GmbH & Co. KG

 

Source

 

Related Articles


Latest Articles

  • Don’t Serve Before Tasting: A Lean Approach to Gated Management for SME Product Launches

    November 6, 2025 By Swathi Mohan, Leanacle Inc. Ever tried serving dinner before tasting it? That’s what many small and mid-sized manufacturers unknowingly do when they rush a new product into production. On paper, everything looks perfect: BOMs finalized, fixtures designed, suppliers lined up. But the first batch rolls out, and suddenly the “dish” tastes wrong: tolerances don’t hold, costs… Read More…

  • 30 Years of RADARSAT Data: Canada’s Legacy in Earth Observation

    November 6, 2025 This year marks a milestone for Canada’s space program: the RADARSAT program is celebrating 30 years of innovation, collaboration, and global impact! Since the launch of RADARSAT-1 on November 4, 1995, RADARSAT satellites have transformed how we observe our planet. They have supported everything from disaster response and climate monitoring to safe navigation at sea and sustainable… Read More…


Featured Article

Revolutionizing Material Movement with Autonomous Mobile Robots

Revolutionizing Material Movement with Autonomous Mobile Robots

In today’s fast-paced manufacturing and logistics industries, the need for efficient and flexible material movement solutions has never been greater. Traditional methods like conveyor systems, forklifts, and manual pushcarts have served us well, but they come with limitations.

That’s why Omron is thrilled to announce the launch of their game-changing MD Series of Autonomous Mobile Robots (AMRs). Read more


Products

  • Moxa’s Vision for Smarter Industrial Network Management

    November 6, 2025 Simplified Management to Optimize Network Operations Building on the insights from Futureproof Your OT with Moxa’s Secure Edge-to-Core Networking, this article highlights how intelligent network management enables scalable, secure, and resilient industrial networks with real-time visibility and simplified control. If you want to manage converged networks, you need to implement user-friendly and scalable… Read More…

  • New Power Supply with IO-Link Interface and Integrated Display Introduced by PULS

    November 6, 2025 PULS’ new CP20.248-IOL is a highly reliable 24 Vdc DIN rail power supply. The device provides efficient and time-saving configuration, operation monitoring and remote control. Using the built-in IO-Link interface and the front panel display, user-defined power supply and application data, such as the AC and DC quality of the system, can be monitored in… Read More…