Siemens Alert
2432Warning Date
Severity Level
Warning Number
Target Sector
14 December, 2021
● Critical
2021-4040
All
Description:
Siemens has released a security alert to address Apache log4j vulnerability in the following products:
- E-Car OC Cloud Application
- EnergyIP Prepay
- Industrial Edge Management App (IEM-App)
- Industrial Edge Management OS (IEM-OS)
- Industrial Edge Manangement Hub
- LOGO! Soft Comfort
- Mendix Applications
- Mindsphere Cloud Application
- Operation Scheduler
- SIGUARD DSA
- SIMATIC WinCC V7.4
- Siveillance Command
- Siveillance Control Pro
- Siveillance Vantage
Threats:
Remote attacker could exploit this vulnerability by executing arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review Siemens security advisory: