December 14, 2021
Critical vulnerability in Apache Log4j library
Log4Shell is a Remote Code Execution (RCE) class vulnerability
Subject: CVE-2021-44228, also named Log4Shell is a Remote Code Execution (RCE) class vulnerability.
CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack.
Updated on 15/February/2022
The latest firmware version 3.15, available for Netman 204 do not use Log4j at all and are therefore not affected by CVE-2021-44228 and CVE-2021-45046.
Other Netman cards do not use log4j at all and are therefore not affected by CVE-2021-44228 and CVE-2021-45046.