Pilz Hardware And Software Not Affected By “Log4Shell” Vulnerability In Software Library Log4j

DCS PILZ Log4Shell Vulnerability 1 400

December 17, 2021

 

Dear Madam or Sir,

 

On December 10th, 2021, the BSI (the German Federal Office for Information Security) published a cyber security alert on the so-called “Log4Shell” vulnerability in the software library Log4j. Log4j is used in many Java applications.

From the BSI alert:

“An IT security vendor blog [LUN2021] reports on vulnerability CVE-2021-44228 [MIT2021] in log4j versions 2.0 through 2.14.1, which may allow attackers to execute their own program code on the target system and thus compromise the server.”

 

Further information is available at:

 

Pilz’s analysis revealed the following:

  • ••Pilz hardware components do not use Java and thus no log4j. Therefore, these components are not affected.
  • ••Pilz Software products partially use log4j versions 2.0 to 2.14.1 (current vulnerability CVE-2021-44228). Analyses to date have shown that it is highly unlikely that the vulnerability can be exploited. If, contrary to expectations, there is a risk, we will publish a security advisory.
  • ••In some Pilz Software products, log4j version 1.2.x is used. The exploitation of the vulnerability in this version (CVE 2021-4104) requires, among other things, a specific configuration. However, this configuration is not used in Pilz Software products.

 

We hope this information is helpful to you. If you have any further questions, please contact our technical support:support@pilz.com.

With best regards

Pilz GmbH & Co. KG

 

Source

 

Related Articles


Latest Articles

  • Helukabel is Pressed for Time

    Helukabel is Pressed for Time

    May 24, 2023 What is sheet metal stamping? The technique of turning sheets of metal into a useful part or component is called sheet metal stamping and is one of the first stages in the automotive assembly process. This is a process in which Helukabel completes regularly. The metal is fed into a press, where… Read More…

  • AGILOX in the Limelight at AUTOMATE 2023

    AGILOX in the Limelight at AUTOMATE 2023

    May 23, 2023 By Krystie Johnston Who is AGILOX? AGILOX is one of the fastest-growing manufacturers of innovative advanced material handling solutions. Their Autonomous Mobile Robots (AMRs) use a highly sophisticated operating system, “X-Swarm Intelligence,” to navigate warehouses and manufacturing facilities and deliver pallets and supplies without needing a centralized fleet management system. This provides… Read More…


Featured Article

Purchasing a Pick and Place Cobot: An Overview of the Benefits, Return on Investment, Pros and Cons, and Gripper Options

Purchasing a Pick and Place Cobot: An Overview of the Benefits, Return on Investment,

As a warehouse or factory owner, you are always looking for ways to improve efficiency, reduce costs, and increase productivity. Investing in a pick and place Cobot could be the solution you have been searching for.

Here you can learn about a few of the key benefits of pick and place Cobots:

Read More


Products