Security Advisory – April, 2022: Neat Statement on the Spring4Shell Exploit
Advisory ID: NEAT-SA-2022-04-21
Publication date: April 21, 2022
Last updated: April 21, 2022
Severity: Critical — CVSS v3.1 Base Score: 9.8, as reported at time of disclosure
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (commonly reported vector for this score; confirm against NVD before publishing)
CVE ID: CVE-2022-22965
Summary
A critical remote code execution vulnerability, known as Spring4Shell or SpringShell, was disclosed in the Java Spring Framework at the end of March 2022. It affects Spring MVC and Spring WebFlux applications running on JDK 9 and later, and could allow an attacker to achieve full control over a compromised system under non-default configurations.
Affected Products
None. Neat does not use the Spring Framework, so Neat devices — including Neat Bar, Neat Pad, Neat Bar Pro, Neat Board, and Neat Frame — are not affected.
Impact
Not applicable to Neat products. In general, exploitation could allow an attacker to access application data, including any connected database, and to move further into an internal network.
Details
Neat’s investigation covered both its own devices and the third-party vendors it uses for client management and sales processes.
Remediation
No action required for Neat products or services.
Acknowledgements
Not applicable.
References
- VMware — CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+
- Spring — Spring Framework RCE, Early Announcement
- CISA — Spring Releases Security Updates Addressing Spring4Shell
- CVE-2022-22965 — CVE Record
Contact
Questions about this advisory can be directed to security@neat.no.