Pilz Hardware And Software Not Affected By “Log4Shell” Vulnerability In Software Library Log4j

DCS PILZ Log4Shell Vulnerability 1 400

December 17, 2021

 

Dear Madam or Sir,

 

On December 10th, 2021, the BSI (the German Federal Office for Information Security) published a cyber security alert on the so-called “Log4Shell” vulnerability in the software library Log4j. Log4j is used in many Java applications.

From the BSI alert:

“An IT security vendor blog [LUN2021] reports on vulnerability CVE-2021-44228 [MIT2021] in log4j versions 2.0 through 2.14.1, which may allow attackers to execute their own program code on the target system and thus compromise the server.”

 

Further information is available at:

 

Pilz’s analysis revealed the following:

  • ••Pilz hardware components do not use Java and thus no log4j. Therefore, these components are not affected.
  • ••Pilz Software products partially use log4j versions 2.0 to 2.14.1 (current vulnerability CVE-2021-44228). Analyses to date have shown that it is highly unlikely that the vulnerability can be exploited. If, contrary to expectations, there is a risk, we will publish a security advisory.
  • ••In some Pilz Software products, log4j version 1.2.x is used. The exploitation of the vulnerability in this version (CVE 2021-4104) requires, among other things, a specific configuration. However, this configuration is not used in Pilz Software products.

 

We hope this information is helpful to you. If you have any further questions, please contact our technical support:support@pilz.com.

With best regards

Pilz GmbH & Co. KG

 

Source

 

Related Articles


Latest Articles

  • Small Town Infrastructure is Being Retrofitted, Federal Funding Helps Drive This Change

    September 9, 2025 By Krystie Johnston Municipalities across Canada are tackling climate change. From big cities to small towns, every action counts. Densely populated metropolitan areas are usually the first places that experience infrastructure upgrades to public buildings and structures because they need to support the increased demands of a growing population. But small towns… Read More…

  • Bossard is Scaling Front Line Flexibility

    September , 2025 Experience Smart Factory Solutions that Adapt to Your Operators’ Needs at FABTECH 2025 By Krystie Johnston Bossard is bringing the future of assembly and inventory management to FABTECH 2025 from September 8 – 11. Visit them at Booth #B13000, at the North Hall in the Automation Pavilion at McCormick Place in Chicago… Read More…


Featured Article

Revolutionizing Material Movement with Autonomous Mobile Robots

Revolutionizing Material Movement with Autonomous Mobile Robots

In today’s fast-paced manufacturing and logistics industries, the need for efficient and flexible material movement solutions has never been greater. Traditional methods like conveyor systems, forklifts, and manual pushcarts have served us well, but they come with limitations.

That’s why Omron is thrilled to announce the launch of their game-changing MD Series of Autonomous Mobile Robots (AMRs). Read more


Products

  • WAGO Expands 750 Series with New Functional Safety I/O Modules

    September 12, 2025 WAGO Expands 750 Series with New Functional Safety I/O Modules WAGO is introducing three functional safety I/O modules to be used with WAGO’s PFC controllers. These new 750 Series modules have four safe inputs along with either two safe outputs at 10 A/24 VDC, or four safe outputs at 2 A/24 VDC… Read More…

  • First Controllers in Trio’s Motion-PLC Range Simplify the Design of Stand-Alone Machines

    September 10, 2025 Trio Motion Technology has launched the first controllers from its new Motion-PLC range, designed to provide advanced motion control performance with the functionality and simplicity of a PLC. The new class of controller combines high-performance motion control over EtherCAT plus logic and I/O expansion, enabling faster, simpler machine development. The first models in… Read More…