CISA Log4j (CVE-2021-44228) Affected Vendor & Software List

March 1, 2022 ยท View on GitHub

0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Status Descriptions

StatusDescription
UnknownStatus unknown. Default choice.
AffectedReported to be affected by CVE-2021-44228.
Not AffectedReported to NOT be affected by CVE-2021-44228 and no further action necessary.
FixedPatch and/or mitigations available (see provided links).
Under InvestigationVendor investigating status.

Software List

This list has been populated using information from the following sources:

  • Kevin Beaumont
  • SwitHak
  • National Cyber Security Centre - Netherlands (NCSC-NL)

NOTE: This file is automatically generated. To submit updates, please refer to CONTRIBUTING.md.

VendorProductAffected VersionsPatched VersionsStatusVendor LinksNotesReferencesReporterLast Updated
UbiquitiUniFi Network Application6.5.53 & lower versionsAffectedlinkcisagov2022-01-12
UbiquitiUniFi Network Controller6.5.54 & lower versionsAffectedlink6.5.54 is reported to still be vulnerable. 6.5.55 is the new recommendation for mitigatin log4j vulnerabilities by updating to log4j 2.16.0cisagov2021-12-15
UbuntuUnknownlinkcisagov2022-01-12
UiPathInSights20.10Affectedlinkcisagov2021-12-15
UmbracoUnknownlinkcisagov2022-01-12
UniFlowUnknownlinkcisagov2022-01-12
Unify ATOSUnknownlinkcisagov2022-01-12
UnimusUnknownlinkcisagov2022-01-12
USSIGNAL MSPUnknownlinkcisagov2022-01-12