Security Advisory – April, 2022: Neat Statement on the Spring4Shell Exploit

Advisory ID: NEAT-SA-2022-04-21
Publication date: April 21, 2022
Last updated: April 21, 2022

Severity: Critical — CVSS v3.1 Base Score: 9.8, as reported at time of disclosure
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (commonly reported vector for this score; confirm against NVD before publishing)
CVE ID: CVE-2022-22965

Summary

A critical remote code execution vulnerability, known as Spring4Shell or SpringShell, was disclosed in the Java Spring Framework at the end of March 2022. It affects Spring MVC and Spring WebFlux applications running on JDK 9 and later, and could allow an attacker to achieve full control over a compromised system under non-default configurations.

Affected Products

None. Neat does not use the Spring Framework, so Neat devices — including Neat Bar, Neat Pad, Neat Bar Pro, Neat Board, and Neat Frame — are not affected.

Impact

Not applicable to Neat products. In general, exploitation could allow an attacker to access application data, including any connected database, and to move further into an internal network.

Details

Neat’s investigation covered both its own devices and the third-party vendors it uses for client management and sales processes.

Remediation

No action required for Neat products or services.

Acknowledgements

Not applicable.

References

Contact

Questions about this advisory can be directed to security@neat.no.