Knowledgebase
Online Technical Support
Software Upgrades: Please check our latest Download section.
Search Tip: You can increase the accuracy of your searches by using as many keywords as possible. Remove any common words such as "a", "or", "the" as they will be used in the search. Do not use any operands such as +, or quotation marks to enclose phrases.
|
Issue:
Perle Systems products are Not Vulnerable to CVE-2021-40228 or CVE-2021-45046 (Apache log4j, Log4Shell).
Apache Log4j <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled (CVE-2021-44228).
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations.(CVE-2021-45046)
Solution:
Perle Systems has confirmed that all products do not incorporate Apache Log4j.
Products impacted:
none
We can provide more information about our products or arrange for a price quotation.
Send an Email Call Us