Pilz Hardware And Software Not Affected By “Log4Shell” Vulnerability In Software Library Log4j

DCS PILZ Log4Shell Vulnerability 1 400

December 17, 2021

 

Dear Madam or Sir,

 

On December 10th, 2021, the BSI (the German Federal Office for Information Security) published a cyber security alert on the so-called “Log4Shell” vulnerability in the software library Log4j. Log4j is used in many Java applications.

From the BSI alert:

“An IT security vendor blog [LUN2021] reports on vulnerability CVE-2021-44228 [MIT2021] in log4j versions 2.0 through 2.14.1, which may allow attackers to execute their own program code on the target system and thus compromise the server.”

 

Further information is available at:

 

Pilz’s analysis revealed the following:

  • ••Pilz hardware components do not use Java and thus no log4j. Therefore, these components are not affected.
  • ••Pilz Software products partially use log4j versions 2.0 to 2.14.1 (current vulnerability CVE-2021-44228). Analyses to date have shown that it is highly unlikely that the vulnerability can be exploited. If, contrary to expectations, there is a risk, we will publish a security advisory.
  • ••In some Pilz Software products, log4j version 1.2.x is used. The exploitation of the vulnerability in this version (CVE 2021-4104) requires, among other things, a specific configuration. However, this configuration is not used in Pilz Software products.

 

We hope this information is helpful to you. If you have any further questions, please contact our technical support:support@pilz.com.

With best regards

Pilz GmbH & Co. KG

 

Source

 

Related Articles


Latest Articles

  • How the NX102 Controller Streamlines Machine Automation with EtherCAT and CIP Safety

    November 12, 2024 In today’s manufacturing landscape, the complexity of machine control systems often leads to increased costs, extended implementation times, and challenging maintenance requirements. Omron’s NX102 Machine Automation Controller addresses these challenges head-on by seamlessly integrating EtherCAT motion control and CIP Safety functionality into a single, powerful platform. Simplified Network Architecture Through Integration The NX102 controller… Read More…

  • 3 Things Manufacturers Should Know About Industry 5.0

    November 12, 2024 While many manufacturers are still embracing the principles of Industry 4.0, the next evolution, Industry 5.0, is already beginning to take shape. Unlike Industry 4.0, which was a giant leap forward in automation and digitalization, Industry 5.0 represents a reconsideration of how smart technology platforms can work alongside humans. This includes technologies like artificial intelligence (AI), the Industrial… Read More…


Featured Article

Revolutionizing Material Movement with Autonomous Mobile Robots

Revolutionizing Material Movement with Autonomous Mobile Robots

In today’s fast-paced manufacturing and logistics industries, the need for efficient and flexible material movement solutions has never been greater. Traditional methods like conveyor systems, forklifts, and manual pushcarts have served us well, but they come with limitations.

That’s why Omron is thrilled to announce the launch of their game-changing MD Series of Autonomous Mobile Robots (AMRs). Read more


Products

  • AM8300 Servomotors Set New High-Water Mark for Performance

    November 15, 2024 For applications requiring especially high speeds and dynamics, Beckhoff offers the water-cooled AM8300 servo series with standstill torques three times greater than conventional options With the AM8300 servomotor series, Beckhoff expands its drive technology portfolio to include modular motors with integrated water cooling. Compared to conventional convection-cooled motors, these devices support higher… Read More…

  • Got to Have a WAGO” – 50 Years of Splicing Connector

    November 14, 2024 Small product, big impact: Five decades ago, the company revolutionized connection technology in electrical installation with the splicing connector. The phrase “Got to have a WAGO” has been firmly anchored in the vocabulary of every professional electrician since its launch in 1974. Even today, “WAGO” stands for speed, safety and maintenance-free operation… Read More…