Pilz Hardware And Software Not Affected By “Log4Shell” Vulnerability In Software Library Log4j

DCS PILZ Log4Shell Vulnerability 1 400

December 17, 2021

 

Dear Madam or Sir,

 

On December 10th, 2021, the BSI (the German Federal Office for Information Security) published a cyber security alert on the so-called “Log4Shell” vulnerability in the software library Log4j. Log4j is used in many Java applications.

From the BSI alert:

“An IT security vendor blog [LUN2021] reports on vulnerability CVE-2021-44228 [MIT2021] in log4j versions 2.0 through 2.14.1, which may allow attackers to execute their own program code on the target system and thus compromise the server.”

 

Further information is available at:

 

Pilz’s analysis revealed the following:

  • ••Pilz hardware components do not use Java and thus no log4j. Therefore, these components are not affected.
  • ••Pilz Software products partially use log4j versions 2.0 to 2.14.1 (current vulnerability CVE-2021-44228). Analyses to date have shown that it is highly unlikely that the vulnerability can be exploited. If, contrary to expectations, there is a risk, we will publish a security advisory.
  • ••In some Pilz Software products, log4j version 1.2.x is used. The exploitation of the vulnerability in this version (CVE 2021-4104) requires, among other things, a specific configuration. However, this configuration is not used in Pilz Software products.

 

We hope this information is helpful to you. If you have any further questions, please contact our technical support:support@pilz.com.

With best regards

Pilz GmbH & Co. KG

 

Source

 

Related Articles


Latest Articles

  • What Is Regenerative Braking?

    December 9, 2025 Regenerative braking is a system that converts kinetic energy – normally lost as heat during braking – into electrical energy that can be stored or reused. Instead of using friction brakes to dissipate energy, the motor functions as a generator during deceleration, reversing the flow of current. The rotational energy from the… Read More…

  • Cyber Resilience Act: Insights from Pilz

    December 4, 2025 The Cyber Resilience Act brings with it a host of new requirements. Which requirements will apply in future? From 11 December 2027, only products that comply with the requirements of the Cyber Resilience Act (CRA) may be placed on the market within the European Union. The CRA contains requirements for the cybersecurity of… Read More…


Featured Article

Revolutionizing Material Movement with Autonomous Mobile Robots

Revolutionizing Material Movement with Autonomous Mobile Robots

In today’s fast-paced manufacturing and logistics industries, the need for efficient and flexible material movement solutions has never been greater. Traditional methods like conveyor systems, forklifts, and manual pushcarts have served us well, but they come with limitations.

That’s why Omron is thrilled to announce the launch of their game-changing MD Series of Autonomous Mobile Robots (AMRs). Read more


Products

  • A One-Stop Shop: Pilz Machine Acceptance Service

    December 10, 2025 Design Risk Assessment, Factory Acceptance Test and Site Acceptance Test Key phases of the design, manufacture and supply of plant and machinery are based on different legal and normative requirements. For this reason, it is important that all legal requirements are met at these points, before the plant/machinery is transferred to the next phase. The legal provisions vary from country… Read More…

  • 3-Phase Voltage Monitoring Relays for HVAC Systems Using Low-GWP Refrigerants from Carlo Gavazzi

    December 10, 2025 Protecting compressors, ensuring compliance, enabling sustainability Carlo Gavazzi Automation, the international electronics group with activities in the design, manufacture and marketing of electronic equipment, announces the launch of its new DPA01, DPA51 and DPA52 three-phase monitoring relays, specifically designed for HVAC systems operating with low-GWP flammable refrigerants. The HVAC industry is undergoing… Read More…