CVE-2021-44228

CVSS V2 High 9.3 CVSS V3 Critical 10
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Overview
  • CVE ID
  • CVE-2021-44228
  • Assigner
  • security@apache.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2021-12-10T10:15:09
  • Last Modified Date
  • 2023-04-03T20:15:07
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* 1 OR 2.0.1 2.3.1
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* 1 OR 2.4.0 2.12.2
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* 1 OR 2.13.0 2.15.0
cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:log4j:2.0:rc2:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:siemens:sppa-t3000_ses3000_firmware:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:siemens:sppa-t3000_ses3000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:a:siemens:captial:*:*:*:*:*:*:*:* 1 OR 2019.1
cpe:2.3:a:siemens:captial:2019.1:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:captial:2019.1:sp1912:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:desigo_cc_advanced_reports:4.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:desigo_cc_advanced_reports:5.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:desigo_cc_info_center:5.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:desigo_cc_info_center:5.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:e-car_operation_center:*:*:*:*:*:*:*:* 1 OR 2021-12-13
cpe:2.3:a:siemens:energy_engage:3.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:energyip:8.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:energyip:8.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:energyip:8.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:energyip:9.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:energyip_prepay:3.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:energyip_prepay:3.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:* 1 OR 8.6.2j-398
cpe:2.3:a:siemens:head-end_system_universal_device_integration_system:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:industrial_edge_management:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:industrial_edge_management_hub:*:*:*:*:*:*:*:* 1 OR 2021-12-13
cpe:2.3:a:siemens:logo\!_soft_comfort:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:mendix:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:mindsphere:*:*:*:*:*:*:*:* 1 OR 2021-12-11
cpe:2.3:a:siemens:navigator:*:*:*:*:*:*:*:* 1 OR 2021-12-13
cpe:2.3:a:siemens:nx:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:opcenter_intelligence:*:*:*:*:*:*:*:* 1 OR 3.2
cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:* 1 OR 1.1.3
cpe:2.3:a:siemens:sentron_powermanager:4.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:sentron_powermanager:4.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:siguard_dsa:4.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:siguard_dsa:4.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:siguard_dsa:4.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:* 1 OR 4.16.2.1
cpe:2.3:a:siemens:siveillance_control_pro:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:siveillance_vantage:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:siveillance_viewpoint:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:solid_edge_cam_pro:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:solid_edge_harness_design:*:*:*:*:*:*:*:* 1 OR 2020
cpe:2.3:a:siemens:solid_edge_harness_design:2020:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:solid_edge_harness_design:2020:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:solid_edge_harness_design:2020:sp2002:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:* 1 OR 4.70
cpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:* 1 OR 2.30
cpe:2.3:a:siemens:spectrum_power_7:2.30:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:spectrum_power_7:2.30:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:spectrum_power_7:2.30:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:vesys:*:*:*:*:*:*:*:* 1 OR 2019.1
cpe:2.3:a:siemens:vesys:2019.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:vesys:2019.1:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:vesys:2019.1:sp1912:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:xpedition_enterprise:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:xpedition_package_integrator:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:a:intel:audio_development_kit:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:intel:computer_vision_annotation_tool:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:intel:data_center_manager:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:intel:genomics_kernel_library:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:intel:oneapi_sample_browser:-:*:*:*:*:eclipse:*:* 1 OR
cpe:2.3:a:intel:secure_device_onboard:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:intel:sensor_solution_firmware_development_kit:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:intel:system_debugger:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:intel:system_studio:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:* 1 OR 10.0.12
AND
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* 1 OR
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* 1 OR
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* 1 OR
cpe:2.3:a:netapp:cloud_insights:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:* 1 OR
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:vmware_vsphere:*:* 1 OR
AND
cpe:2.3:a:cisco:advanced_malware_protection_virtual_private_cloud_appliance:*:*:*:*:*:*:*:* 1 OR 3.5.4
cpe:2.3:a:cisco:automated_subsea_tuning:*:*:*:*:*:*:*:* 1 OR 2.1.0
cpe:2.3:a:cisco:broadworks:*:*:*:*:*:*:*:* 1 OR 2021.11_1.162
cpe:2.3:a:cisco:business_process_automation:*:*:*:*:*:*:*:* 1 OR 3.0.000.115
cpe:2.3:a:cisco:business_process_automation:*:*:*:*:*:*:*:* 1 OR 3.1.000.000 3.1.000.044
cpe:2.3:a:cisco:business_process_automation:*:*:*:*:*:*:*:* 1 OR 3.2.000.000 3.2.000.009
cpe:2.3:a:cisco:cloud_connect:*:*:*:*:*:*:*:* 1 OR 12.6\(1\)
cpe:2.3:a:cisco:cloudcenter:*:*:*:*:*:*:*:* 1 OR 4.10.0.16
cpe:2.3:a:cisco:cloudcenter_cost_optimizer:*:*:*:*:*:*:*:* 1 OR 5.5.2
cpe:2.3:a:cisco:cloudcenter_suite_admin:*:*:*:*:*:*:*:* 1 OR 5.3.1
cpe:2.3:a:cisco:cloudcenter_workload_manager:*:*:*:*:*:*:*:* 1 OR 5.5.2
cpe:2.3:a:cisco:common_services_platform_collector:*:*:*:*:*:*:*:* 1 OR 2.9.1.3
cpe:2.3:a:cisco:common_services_platform_collector:*:*:*:*:*:*:*:* 1 OR 2.10.0 2.10.0.1
cpe:2.3:a:cisco:connected_mobile_experiences:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:contact_center_domain_manager:*:*:*:*:*:*:*:* 1 OR 12.5\(1\)
cpe:2.3:a:cisco:contact_center_management_portal:*:*:*:*:*:*:*:* 1 OR 12.5\(1\)
cpe:2.3:a:cisco:crosswork_data_gateway:*:*:*:*:*:*:*:* 1 OR 2.0.2
cpe:2.3:a:cisco:crosswork_data_gateway:3.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:crosswork_network_controller:*:*:*:*:*:*:*:* 1 OR 2.0.1
cpe:2.3:a:cisco:crosswork_network_controller:3.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:crosswork_optimization_engine:*:*:*:*:*:*:*:* 1 OR 2.0.1
cpe:2.3:a:cisco:crosswork_optimization_engine:3.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:crosswork_platform_infrastructure:*:*:*:*:*:*:*:* 1 OR 4.0.1
cpe:2.3:a:cisco:crosswork_platform_infrastructure:4.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:crosswork_zero_touch_provisioning:*:*:*:*:*:*:*:* 1 OR 2.0.1
cpe:2.3:a:cisco:crosswork_zero_touch_provisioning:3.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:customer_experience_cloud_agent:*:*:*:*:*:*:*:* 1 OR 1.12.1
cpe:2.3:a:cisco:cyber_vision_sensor_management_extension:*:*:*:*:*:*:*:* 1 OR 4.0.3
cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:* 1 OR 11.3\(1\)
cpe:2.3:a:cisco:data_center_network_manager:11.3\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:dna_center:*:*:*:*:*:*:*:* 1 OR 2.1.2.8
cpe:2.3:a:cisco:dna_center:*:*:*:*:*:*:*:* 1 OR 2.2.2.0 2.2.2.8
cpe:2.3:a:cisco:dna_center:*:*:*:*:*:*:*:* 1 OR 2.2.3.0 2.2.3.4
cpe:2.3:a:cisco:dna_spaces\:_connector:*:*:*:*:*:*:*:* 1 OR 2.5
cpe:2.3:a:cisco:emergency_responder:*:*:*:*:*:*:*:* 1 OR 11.5\(4\)
cpe:2.3:a:cisco:enterprise_chat_and_email:*:*:*:*:*:*:*:* 1 OR 12.0\(1\)
cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:* 1 OR 4.1.1
cpe:2.3:a:cisco:finesse:*:*:*:*:*:*:*:* 1 OR 12.6\(1\)
cpe:2.3:a:cisco:finesse:12.6\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:fog_director:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:* 1 OR 2.4.0
cpe:2.3:a:cisco:identity_services_engine:2.4.0:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:integrated_management_controller_supervisor:*:*:*:*:*:*:*:* 1 OR 2.3.2.1
cpe:2.3:a:cisco:intersight_virtual_appliance:*:*:*:*:*:*:*:* 1 OR 1.0.9-361
cpe:2.3:a:cisco:iot_operations_dashboard:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_assurance_engine:*:*:*:*:*:*:*:* 1 OR 6.0.2
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* 1 OR 5.3.5.1
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* 1 OR 5.4 5.4.5.2
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* 1 OR 5.5 5.5.4.1
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* 1 OR 5.6 5.6.3.1
cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:* 1 OR 2.1.2
cpe:2.3:a:cisco:nexus_insights:*:*:*:*:*:*:*:* 1 OR 6.0.2
cpe:2.3:a:cisco:optical_network_controller:*:*:*:*:*:*:*:* 1 OR 1.1.0
cpe:2.3:a:cisco:packaged_contact_center_enterprise:*:*:*:*:*:*:*:* 1 OR 11.6
cpe:2.3:a:cisco:packaged_contact_center_enterprise:11.6\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:paging_server:*:*:*:*:*:*:*:* 1 OR 14.4.1
cpe:2.3:a:cisco:prime_service_catalog:*:*:*:*:*:*:*:* 1 OR 12.1
cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:* 1 OR 20.3.4.1
cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:* 1 OR 20.4 20.4.2.1
cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:* 1 OR 20.5 20.5.1.1
cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:* 1 OR 20.6 20.6.2.1
cpe:2.3:a:cisco:smart_phy:*:*:*:*:*:*:*:* 1 OR 3.2.1
cpe:2.3:a:cisco:ucs_central:*:*:*:*:*:*:*:* 1 OR 2.0\(1p\)
cpe:2.3:a:cisco:ucs_director:*:*:*:*:*:*:*:* 1 OR 6.8.2.0
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:* 1 OR 11.5\(1\)
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:* 1 OR 11.5\(1\)
cpe:2.3:a:cisco:unified_communications_manager:11.5\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager:11.5\(1\):*:*:*:-:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager:11.5\(1\):*:*:*:session_management:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager:11.5\(1\)su3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:*:*:*:*:*:*:*:* 1 OR 11.5\(1\)
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_enterprise:*:*:*:*:*:*:*:* 1 OR 11.6\(2\)
cpe:2.3:a:cisco:unified_contact_center_enterprise:11.6\(2\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_express:*:*:*:*:*:*:*:* 1 OR 12.5\(1\)
cpe:2.3:a:cisco:unified_customer_voice_portal:*:*:*:*:*:*:*:* 1 OR 11.6
cpe:2.3:a:cisco:unified_customer_voice_portal:11.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_customer_voice_portal:12.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_customer_voice_portal:12.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unity_connection:*:*:*:*:*:*:*:* 1 OR 11.5\(1\)
cpe:2.3:a:cisco:video_surveillance_operations_manager:*:*:*:*:*:*:*:* 1 OR 7.14.4
cpe:2.3:a:cisco:virtual_topology_system:*:*:*:*:*:*:*:* 1 OR 2.6.7
cpe:2.3:a:cisco:virtualized_infrastructure_manager:*:*:*:*:*:*:*:* 1 OR 3.2.0
cpe:2.3:a:cisco:virtualized_infrastructure_manager:*:*:*:*:*:*:*:* 1 OR 3.4.0 3.4.4
cpe:2.3:a:cisco:virtualized_voice_browser:*:*:*:*:*:*:*:* 1 OR 12.5\(1\)
cpe:2.3:a:cisco:wan_automation_engine:*:*:*:*:*:*:*:* 1 OR 7.3.0.2
cpe:2.3:a:cisco:webex_meetings_server:*:*:*:*:*:*:*:* 1 OR 3.0
cpe:2.3:a:cisco:webex_meetings_server:3.0:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release1:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release2:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3:-:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3_security_patch4:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3_security_patch5:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3_service_pack_2:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3_service_pack_3:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release4:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:4.0:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_release1:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_release2:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_release3:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:workload_optimization_manager:*:*:*:*:*:*:*:* 1 OR 3.2.1
cpe:2.3:o:cisco:unified_intelligence_center:*:*:*:*:*:*:*:* 1 OR 12.6\(1\)
cpe:2.3:o:cisco:unified_sip_proxy:*:*:*:*:*:*:*:* 1 OR 10.2.1v2
cpe:2.3:o:cisco:unified_workforce_optimization:*:*:*:*:*:*:*:* 1 OR 11.5\(1\)
AND
cpe:2.3:o:cisco:fxos:6.2.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:cisco:fxos:6.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:cisco:fxos:6.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:cisco:fxos:6.5.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:cisco:fxos:6.6.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:cisco:fxos:6.7.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:cisco:fxos:7.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:cisco:fxos:7.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:cisco:firepower_1010:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_1120:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_1140:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_1150:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_2110:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_2120:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_2130:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_2140:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_4110:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_4112:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_4115:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_4120:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_4125:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_4140:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_4145:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_4150:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:cisco:firepower_9300:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:a:cisco:automated_subsea_tuning:02.01.00:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:broadworks:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:cloudcenter_suite:4.10\(0.15\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:cloudcenter_suite:5.3\(0\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:cloudcenter_suite:5.4\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:cloudcenter_suite:5.5\(0\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:cloudcenter_suite:5.5\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:common_services_platform_collector:002.009\(000.000\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:common_services_platform_collector:002.009\(000.001\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:common_services_platform_collector:002.009\(000.002\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:common_services_platform_collector:002.009\(001.000\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:common_services_platform_collector:002.009\(001.001\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:common_services_platform_collector:002.009\(001.002\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:common_services_platform_collector:002.010\(000.000\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:006.004.000.003:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:006.005.000.:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:006.005.000.000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:007.000.001:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:007.001.000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:007.002.000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:007.003.000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:007.003.001.001:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:007.003.003:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:008.000.000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:connected_analytics_for_network_deployment:008.000.000.000.004:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:crosswork_network_automation:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:crosswork_network_automation:2.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:crosswork_network_automation:3.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:crosswork_network_automation:4.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:crosswork_network_automation:4.1.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:cx_cloud_agent:001.012:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:cyber_vision:4.0.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:cyber_vision_sensor_management_extension:4.0.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:dna_center:2.2.2.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:dna_spaces:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:dna_spaces_connector:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:emergency_responder:11.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:emergency_responder:11.5\(4.65000.14\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:emergency_responder:11.5\(4.66000.14\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:enterprise_chat_and_email:12.0\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:enterprise_chat_and_email:12.5\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:enterprise_chat_and_email:12.6\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:evolved_programmable_network_manager:3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:evolved_programmable_network_manager:3.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:evolved_programmable_network_manager:4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:evolved_programmable_network_manager:4.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:evolved_programmable_network_manager:5.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:evolved_programmable_network_manager:5.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:finesse:12.5\(1\):su1:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:finesse:12.5\(1\):su2:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:finesse:12.6\(1\):-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:finesse:12.6\(1\):es01:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:finesse:12.6\(1\):es02:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:finesse:12.6\(1\):es03:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:firepower_threat_defense:6.2.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:firepower_threat_defense:6.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:firepower_threat_defense:6.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:firepower_threat_defense:6.5.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:firepower_threat_defense:6.6.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:firepower_threat_defense:6.7.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:firepower_threat_defense:7.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:firepower_threat_defense:7.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:identity_services_engine:002.004\(000.914\):-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:identity_services_engine:002.006\(000.156\):-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:identity_services_engine:002.007\(000.356\):-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:identity_services_engine:003.000\(000.458\):-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:identity_services_engine:003.001\(000.518\):-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:identity_services_engine:003.002\(000.116\):-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:integrated_management_controller_supervisor:002.003\(002.000\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:integrated_management_controller_supervisor:2.3.2.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:intersight_virtual_appliance:1.0.9-343:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:mobility_services_engine:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_assurance_engine:6.0\(2.1912\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.0\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.1\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.2\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.3\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.4\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.5\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.5\(2\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_dashboard_fabric_controller:11.5\(3\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_insights_for_data_center:6.0\(2.1914\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:network_services_orchestrator:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:optical_network_controller:1.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:paging_server:8.3\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:paging_server:8.4\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:paging_server:8.5\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:paging_server:9.0\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:paging_server:9.0\(2\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:paging_server:9.1\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:paging_server:12.5\(2\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:paging_server:14.0\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:prime_service_catalog:12.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:sd-wan_vmanage:20.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:sd-wan_vmanage:20.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:sd-wan_vmanage:20.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:sd-wan_vmanage:20.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:sd-wan_vmanage:20.6.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:sd-wan_vmanage:20.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:sd-wan_vmanage:20.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:smart_phy:3.1.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:smart_phy:3.1.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:smart_phy:3.1.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:smart_phy:3.1.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:smart_phy:3.2.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:smart_phy:21.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0\(1a\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0\(1b\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0\(1c\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0\(1d\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0\(1e\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0\(1f\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0\(1g\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0\(1h\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0\(1k\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:ucs_central_software:2.0\(1l\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.17900.52\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.18119.2\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.18900.97\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.21900.40\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.22900.28\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager_im_\&_presence_service:11.5\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_communications_manager_im_\&_presence_service:11.5\(1.22900.6\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_computing_system:006.008\(001.000\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_enterprise:11.6\(2\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_enterprise:12.0\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_enterprise:12.5\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_enterprise:12.6\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_enterprise:12.6\(2\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_express:12.5\(1\):-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_express:12.5\(1\):su1:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_express:12.6\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_express:12.6\(2\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_contact_center_management_portal:12.6\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_customer_voice_portal:11.6\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_customer_voice_portal:12.0\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_customer_voice_portal:12.5\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_customer_voice_portal:12.6\(1\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_intelligence_center:12.6\(1\):-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_intelligence_center:12.6\(1\):es01:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_intelligence_center:12.6\(1\):es02:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_intelligence_center:12.6\(2\):-:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_sip_proxy:010.000\(000\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_sip_proxy:010.000\(001\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_sip_proxy:010.002\(000\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_sip_proxy:010.002\(001\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unified_workforce_optimization:11.5\(1\):sr7:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unity_connection:11.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:unity_connection:11.5\(1.10000.6\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:video_surveillance_manager:7.14\(1.26\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:video_surveillance_manager:7.14\(2.26\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:video_surveillance_manager:7.14\(3.025\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:video_surveillance_manager:7.14\(4.018\):*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:virtual_topology_system:2.6.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:wan_automation_engine:7.1.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:wan_automation_engine:7.2.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:wan_automation_engine:7.2.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:wan_automation_engine:7.2.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:wan_automation_engine:7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:wan_automation_engine:7.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:wan_automation_engine:7.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:wan_automation_engine:7.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:cisco:webex_meetings_server:4.0:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:a:snowsoftware:snow_commander:*:*:*:*:*:*:*:* 1 OR 8.10.0
cpe:2.3:a:snowsoftware:vm_access_proxy:*:*:*:*:*:*:*:* 1 OR 3.6
AND
cpe:2.3:a:bentley:synchro:*:*:*:*:pro:*:*:* 1 OR 6.1 6.4.3.2
cpe:2.3:a:bentley:synchro_4d:*:*:*:*:pro:*:*:* 1 OR 6.2.4.2
AND
cpe:2.3:a:percussion:rhythmyx:*:*:*:*:*:*:*:* 1 OR 7.3.2
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:C/I:C/A:C
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • COMPLETE
  • Integrity Impact
  • COMPLETE
  • Availability Impact
  • COMPLETE
  • Base Score
  • 9.3
  • Severity
  • HIGH
  • Exploitability Score
  • 8.6
  • Impact Score
  • 10
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • CHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • HIGH
  • Base Score
  • 10
  • Base Severity
  • CRITICAL
  • Exploitability Score
  • 3.9
  • Impact Score
  • 6
References
Reference URL Reference Tags
http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html
http://seclists.org/fulldisclosure/2022/Dec/2 Exploit Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2022/Jul/11 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2022/Mar/23 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/1 Mailing List Mitigation Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/2 Mailing List Mitigation Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/3 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/13/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/13/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/14/4 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/15/3 Mailing List Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf Third Party Advisory
https://github.com/cisagov/log4j-affected-db Third Party Advisory
https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md Product US Government Resource
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228 Exploit Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB/ Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM/ Third Party Advisory
https://logging.apache.org/log4j/2.x/security.html Release Notes Vendor Advisory
https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/ Patch Third Party Advisory Vendor Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032 Third Party Advisory
https://security.netapp.com/advisory/ntap-20211210-0007/ Vendor Advisory
https://support.apple.com/kb/HT213189 Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://twitter.com/kurtseifried/status/1469345530182455296 Exploit Third Party Advisory
https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001 Third Party Advisory
https://www.debian.org/security/2021/dsa-5020 Third Party Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html Third Party Advisory
https://www.kb.cert.org/vuls/id/930724 Third Party Advisory US Government Resource
https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html Exploit Third Party Advisory
https://www.oracle.com/security-alerts/alert-cve-2021-44228.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Third Party Advisory
History
Created Old Value New Value Data Type Notes
2022-04-20 16:58:51 Added to TrackCVE
2022-12-06 03:31:08 2021-12-10T10:15Z 2021-12-10T10:15:09 CVE Published Date updated
2022-12-06 03:31:08 2022-08-17T17:46:12 CVE Modified Date updated
2022-12-06 03:31:08 Analyzed Vulnerability Status updated
2022-12-06 03:31:20 References updated
2022-12-09 05:20:26 2022-12-09T05:15:11 CVE Modified Date updated
2022-12-09 05:20:26 Analyzed Modified Vulnerability Status updated
2022-12-09 05:20:27 CWE-20 Weakness Enumeration updated
2022-12-09 05:20:30 References updated
2022-12-12 18:14:41 Modified Undergoing Analysis Vulnerability Status updated
2023-02-06 19:13:45 2023-02-06T18:53:16 CVE Modified Date updated
2023-02-06 19:13:45 Undergoing Analysis Analyzed Vulnerability Status updated
2023-02-06 19:13:45 Weakness Enumeration update
2023-04-04 13:09:59 2023-04-03T20:15:07 CVE Modified Date updated
2023-04-04 13:09:59 Analyzed Modified Vulnerability Status updated
2023-04-04 13:10:02 References updated