Security Advisory – December, 2021: Log4Shell exploit

Advisory ID: NEAT-SA-2021-12-14
Publication date: December 14, 2021
Last updated: December 14, 2021

Severity: Critical — CVSS v3.1 Base Score: 10.0
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID: CVE-2021-44228

Summary

A critical zero-day vulnerability was disclosed in Log4j, a widely used open-source Java logging library, and was being actively exploited across the internet at the time of disclosure, putting many organizations at risk.

Affected Products

None. Neat does not run the Log4j library on any of its servers or devices.

Impact

Not applicable to Neat products or services. Neat reviewed its hardware devices, environments, services, and cloud platforms and found no direct exposure to this exploit.

Details

Neat also reached out to the third-party vendors it uses for client management and sales processes to assess their exposure, and worked with Zoom and Microsoft to confirm that Teams and Zoom were unaffected at the time.

Remediation

No action required for Neat devices.

Acknowledgements

Not applicable.

References

Contact

Questions about this advisory can be directed to security@neat.no.