Security Advisory – December, 2021: Log4Shell exploit
Advisory ID: NEAT-SA-2021-12-14
Publication date: December 14, 2021
Last updated: December 14, 2021
Severity: Critical — CVSS v3.1 Base Score: 10.0
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID: CVE-2021-44228
Summary
A critical zero-day vulnerability was disclosed in Log4j, a widely used open-source Java logging library, and was being actively exploited across the internet at the time of disclosure, putting many organizations at risk.
Affected Products
None. Neat does not run the Log4j library on any of its servers or devices.
Impact
Not applicable to Neat products or services. Neat reviewed its hardware devices, environments, services, and cloud platforms and found no direct exposure to this exploit.
Details
Neat also reached out to the third-party vendors it uses for client management and sales processes to assess their exposure, and worked with Zoom and Microsoft to confirm that Teams and Zoom were unaffected at the time.
Remediation
No action required for Neat devices.
Acknowledgements
Not applicable.
References
Contact
Questions about this advisory can be directed to security@neat.no.