Pilz Hardware And Software Not Affected By “Log4Shell” Vulnerability In Software Library Log4j

DCS PILZ Log4Shell Vulnerability 1 400

December 17, 2021

 

Dear Madam or Sir,

 

On December 10th, 2021, the BSI (the German Federal Office for Information Security) published a cyber security alert on the so-called “Log4Shell” vulnerability in the software library Log4j. Log4j is used in many Java applications.

From the BSI alert:

“An IT security vendor blog [LUN2021] reports on vulnerability CVE-2021-44228 [MIT2021] in log4j versions 2.0 through 2.14.1, which may allow attackers to execute their own program code on the target system and thus compromise the server.”

 

Further information is available at:

 

Pilz’s analysis revealed the following:

  • ••Pilz hardware components do not use Java and thus no log4j. Therefore, these components are not affected.
  • ••Pilz Software products partially use log4j versions 2.0 to 2.14.1 (current vulnerability CVE-2021-44228). Analyses to date have shown that it is highly unlikely that the vulnerability can be exploited. If, contrary to expectations, there is a risk, we will publish a security advisory.
  • ••In some Pilz Software products, log4j version 1.2.x is used. The exploitation of the vulnerability in this version (CVE 2021-4104) requires, among other things, a specific configuration. However, this configuration is not used in Pilz Software products.

 

We hope this information is helpful to you. If you have any further questions, please contact our technical support:support@pilz.com.

With best regards

Pilz GmbH & Co. KG

 

Source

 

Related Articles


Latest Articles

  • Cloud Computing vs Edge Computing: Driving Predictive Maintenance, Remote Diagnostics, and Device Safety

    November 19, 2025 Cloud computing and edge computing are reshaping how industrial organizations manage connected devices, analyze data, and maintain operations. While both architectures process and store data, they differ significantly in where that processing occurs—centrally in the cloud or locally at the edge. Understanding these differences is critical for companies evaluating strategies for predictive… Read More…

  • The Power of OMRON’s Sysmac Studio: Unify Automation and Integrate Safety

    November 7, 2025 By Omron Automation Industry moves fast. Outpace obsolescence with OMRON’s Sysmac Studio. Designed to empower operations from the edge to the cloud, it unifies automation by prioritizing safety and security. Built for today, ready for the future. Today, the factory floor faces pressure from suppliers, consumers, competition, and emerging technologies. Operation teams are looking… Read More…


Featured Article

Revolutionizing Material Movement with Autonomous Mobile Robots

Revolutionizing Material Movement with Autonomous Mobile Robots

In today’s fast-paced manufacturing and logistics industries, the need for efficient and flexible material movement solutions has never been greater. Traditional methods like conveyor systems, forklifts, and manual pushcarts have served us well, but they come with limitations.

That’s why Omron is thrilled to announce the launch of their game-changing MD Series of Autonomous Mobile Robots (AMRs). Read more


Products

  • New Software, New Portfolio: the Eplan Platform 2026

    November 19, 2025 More of Everything and Perfectly Customised. The new Eplan Platform 2026 is here! Eplan has used this opportunity to completely redevelop its entire portfolio, with an even greater focus on customers and their requirements in their respective market segments. One central point is the significant reduction in complexity. The new software portfolio… Read More…

  • Rockwell Automation to Advance Industrial Intelligence Through Edge-based Generative AI with Nvidia Nemotron

    November 19, 2025 Rockwell Automation, Inc. (NYSE: ROK), one of the world’s largest companies dedicated to industrial automation and digital transformation, has announced a breakthrough in bringing generative AI directly to the industrial edge. Rockwell is introducing its integration of NVIDIA Nemotron Nano, a purpose-built small language model (SLM) optimized for FactoryTalk® Design Studio™ and other Rockwell product… Read More…