Pilz Hardware And Software Not Affected By “Log4Shell” Vulnerability In Software Library Log4j

DCS PILZ Log4Shell Vulnerability 1 400

December 17, 2021

 

Dear Madam or Sir,

 

On December 10th, 2021, the BSI (the German Federal Office for Information Security) published a cyber security alert on the so-called “Log4Shell” vulnerability in the software library Log4j. Log4j is used in many Java applications.

From the BSI alert:

“An IT security vendor blog [LUN2021] reports on vulnerability CVE-2021-44228 [MIT2021] in log4j versions 2.0 through 2.14.1, which may allow attackers to execute their own program code on the target system and thus compromise the server.”

 

Further information is available at:

 

Pilz’s analysis revealed the following:

  • ••Pilz hardware components do not use Java and thus no log4j. Therefore, these components are not affected.
  • ••Pilz Software products partially use log4j versions 2.0 to 2.14.1 (current vulnerability CVE-2021-44228). Analyses to date have shown that it is highly unlikely that the vulnerability can be exploited. If, contrary to expectations, there is a risk, we will publish a security advisory.
  • ••In some Pilz Software products, log4j version 1.2.x is used. The exploitation of the vulnerability in this version (CVE 2021-4104) requires, among other things, a specific configuration. However, this configuration is not used in Pilz Software products.

 

We hope this information is helpful to you. If you have any further questions, please contact our technical support:support@pilz.com.

With best regards

Pilz GmbH & Co. KG

 

Source

 

Related Articles


Latest Articles

  • Thermal Imaging for Data Centres

    February 18, 2025 Thermal Imaging for Data Centres Data centre maintenance teams have a big share in safeguarding the critical resource that customers and businesses depend upon. Fortunately, they have one secret weapon that enables them to spot issues in an early stage before they turn into big problems: FLIR thermal imaging. The data centre… Read More…

  • Rockwell’s Three Smart Factory Trends that Pay Big Dividends

    February 13, 2025 Networked motor control center technology accelerates ROI, productivity, savings & safety. Rockwell Automation has seen manufacturers around the globe investing billions of dollars in smart manufacturing and production plants. Industry experts project the demand for smart factories will double by 2032 to $322 billion because of the increased return on investment. At the heart… Read More…


Featured Article

Revolutionizing Material Movement with Autonomous Mobile Robots

Revolutionizing Material Movement with Autonomous Mobile Robots

In today’s fast-paced manufacturing and logistics industries, the need for efficient and flexible material movement solutions has never been greater. Traditional methods like conveyor systems, forklifts, and manual pushcarts have served us well, but they come with limitations.

That’s why Omron is thrilled to announce the launch of their game-changing MD Series of Autonomous Mobile Robots (AMRs). Read more


Products

  • PSENslock 2: Switch to the New Generation Now

    February 20, 2025 Safety locking device PSENslock 2 – Generational change made simple! Already using the electromagnetic safety locking device PSENslock? Then you’ll be convinced by the new generation PSENslock 2, which offers you even more features and can be integrated to fit your application precisely. In the video you’ll see how you can quickly… Read More…

  • celduc Is Pleased to Launch Their New Product Catalogue

    February 20, 2025 celduc is pleased to announce the launch of their new Product Guide, featuring their most up-to-date range of products. This guide is designed to give you the latest product knowledge and technical specifications, making it easier for you to find the perfect solutions for your projects. This Product Guide provides everything you… Read More…