EXPOSURES › CVE-2021-44228
CVE-2021-44228
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
◐ ZERO-DAY
⌖ EXPLOITED IN THE WILD
SHAME 95/100
ransomwarerceexploited-in-wild
The Log4j2 vulnerability allowed attackers to execute arbitrary code on vulnerable systems remotely.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
AFFECTED FEDRAMP PRODUCTS · 10
| PRODUCT | STATUS |
|---|---|
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Cloud Insights NetApp |
In Process |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| Mendix Cloud for Government Siemens Government Technologies |
In Process |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |