CVE-2021-44228

Published Dec 10, 2021

Last updated 5 days ago

Exploit knownCVSS critical 10.0
Log4Shell
Server
VDI
Supply chain
API
Docker
Zero-day
Network
Open source
hsm
web application
Sonicwall
SMTP
Cloud
sca
IoT
Port (443)
Port (80)

Overview

Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Source
security@apache.org
NVD status
Analyzed
Products
6bk1602-0aa12-0tp0_firmware, 6bk1602-0aa22-0tp0_firmware, 6bk1602-0aa32-0tp0_firmware, 6bk1602-0aa42-0tp0_firmware, 6bk1602-0aa52-0tp0_firmware, log4j, sppa-t3000_ses3000_firmware, capital, comos, desigo_cc_advanced_reports, desigo_cc_info_center, e-car_operation_center, energy_engage, energyip, energyip_prepay, gma-manager, head-end_system_universal_device_integration_system, industrial_edge_management, industrial_edge_management_hub, logo\!_soft_comfort, mendix, mindsphere, navigator, nx, opcenter_intelligence, operation_scheduler, sentron_powermanager, siguard_dsa, sipass_integrated, siveillance_command, siveillance_control_pro, siveillance_identity, siveillance_vantage, siveillance_viewpoint, solid_edge_cam_pro, solid_edge_harness_design, spectrum_power_4, spectrum_power_7, teamcenter, vesys, xpedition_enterprise, xpedition_package_integrator, computer_vision_annotation_tool, datacenter_manager, genomics_kernel_library, oneapi_sample_browser, secure_device_onboard, system_studio, debian_linux, fedora, email_security, active_iq_unified_manager, brocade_san_navigator, cloud_insights, cloud_manager, cloud_secure_agent, oncommand_insight, ontap_tools, snapcenter, solidfire_\&_hci_storage_node, solidfire_enterprise_sds, advanced_malware_protection_virtual_private_cloud_appliance, automated_subsea_tuning, broadworks, business_process_automation, cloud_connect, cloudcenter, cloudcenter_cost_optimizer, cloudcenter_suite_admin, cloudcenter_workload_manager, common_services_platform_collector, connected_mobile_experiences, contact_center_domain_manager, contact_center_management_portal, crosswork_data_gateway, crosswork_network_controller, crosswork_optimization_engine, crosswork_platform_infrastructure, crosswork_zero_touch_provisioning, customer_experience_cloud_agent, cyber_vision_sensor_management_extension, data_center_network_manager, dna_center, dna_spaces\, emergency_responder, enterprise_chat_and_email, evolved_programmable_network_manager, finesse, fog_director, identity_services_engine, integrated_management_controller_supervisor, intersight_virtual_appliance, iot_operations_dashboard, network_assurance_engine, network_services_orchestrator, nexus_dashboard, nexus_insights, optical_network_controller, packaged_contact_center_enterprise, paging_server, prime_service_catalog, sd-wan_vmanage, smart_phy, ucs_central, ucs_director, unified_communications_manager, unified_communications_manager_im_and_presence_service, unified_contact_center_enterprise, unified_contact_center_express, unified_customer_voice_portal, unified_intelligence_center, unity_connection, video_surveillance_operations_manager, virtual_topology_system, virtualized_infrastructure_manager, virtualized_voice_browser, wan_automation_engine, webex_meetings_server, workload_optimization_manager, unified_sip_proxy, unified_workforce_optimization, fxos, cloudcenter_suite, crosswork_network_automation, cx_cloud_agent, cyber_vision, dna_spaces, dna_spaces_connector, mobility_services_engine, network_dashboard_fabric_controller, network_insights_for_data_center, secure_firewall_threat_defense, ucs_central_software, unified_communications_manager_im_\&_presence_service, unified_computing_system, unified_contact_center_management_portal, video_surveillance_manager, snow_commander, vm_access_proxy, synchro, synchro_4d, rhythmyx, xcode

Insights

Analysis from the Intruder Security Team
Published Oct 15, 2024

Log4j is a remote code execution vulnerability, in the popular log4j package, which is everywhere.

More information is available in our blog post here.

Risk scores

CVSS 3.1

Type
Primary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

CVSS 2.0

Type
Primary
Base score
9.3
Impact score
10
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:C/I:C/A:C

Known exploits

Data from CISA

Vulnerability name
Apache Log4j2 Remote Code Execution Vulnerability
Exploit added on
Dec 10, 2021
Exploit action due
Dec 24, 2021
Required action
For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

Weaknesses

security@apache.org
CWE-20
nvd@nist.gov
CWE-917

Social media

Hype score
Not currently trending
  1. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-gXcrY61 ( CVE-2021-44228 ) EGE-GH-mlHKBE9 ( CVE-2021-44228 ) EGE-GH-UkC3bPM ( CVE-2026-57827 ) EGE-GH-kQvdrdy ( CVE-2021-21972 ) EGE-GH-UzPcxEL ( CVE-2023-33246 ) ..🧵👇

    @exploitgrid

    4 Aug 2026

    35 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: #EGE-GH-2hTfkzq ( CVE-2026-57827 ) EGE-GH-p5IA4H4 ( CVE-2026-57811 ) EGE-GH-uLGqWw2 ( CVE-2018-4013 ) EGE-GH-H7DtJPV ( CVE-2018-4013 ) EGE-GH-arkHFzA ( CVE-2021-44228 ) ..🧵👇

    @exploitgrid

    31 Jul 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Log4j (CVE-2021-44228) is still being exploited in 2025. Four years after disclosure, unpatched systems remain active targets. Legacy vulnerabilities with easy exploitation never stop being targeted. Patch everything. #Log4j #LegacyVulns

    @theGreyHatter

    29 Jun 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2021-44228 patch rates hit 93% within 90 days. Looks good. The 7% remainder is your internet-facing Log4j in a forgotten vendor appliance nobody owns. That's where shells still live in 2025. https://t.co/IOmgnVFkBG

    @paul_fregonese

    9 Jun 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. نسخه جدید باج افزار DragonForce منتشر شده است که از آسیب پذیری هایی با کدهای شناسایی CVE-2021-44228 و CVE-2023-46805 و CVE-2024-21887 استفاده می کند. برای حفظ دسترسی خود از بدافزاری

    @AmirHossein_sec

    10 May 2025

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.