Pilz Hardware And Software Not Affected By “Log4Shell” Vulnerability In Software Library Log4j

December 17, 2021

 

Dear Madam or Sir,

 

On December 10th, 2021, the BSI (the German Federal Office for Information Security) published a cyber security alert on the so-called “Log4Shell” vulnerability in the software library Log4j. Log4j is used in many Java applications.

From the BSI alert:

“An IT security vendor blog [LUN2021] reports on vulnerability CVE-2021-44228 [MIT2021] in log4j versions 2.0 through 2.14.1, which may allow attackers to execute their own program code on the target system and thus compromise the server.”

 

Further information is available at:

 

Pilz’s analysis revealed the following:

  • ••Pilz hardware components do not use Java and thus no log4j. Therefore, these components are not affected.
  • ••Pilz Software products partially use log4j versions 2.0 to 2.14.1 (current vulnerability CVE-2021-44228). Analyses to date have shown that it is highly unlikely that the vulnerability can be exploited. If, contrary to expectations, there is a risk, we will publish a security advisory.
  • ••In some Pilz Software products, log4j version 1.2.x is used. The exploitation of the vulnerability in this version (CVE 2021-4104) requires, among other things, a specific configuration. However, this configuration is not used in Pilz Software products.

 

We hope this information is helpful to you. If you have any further questions, please contact our technical support:support@pilz.com.

With best regards

Pilz GmbH & Co. KG

 

Source

 

Related Articles



Editor’s Pick: Featured Article

Weidmüller’s u-control 2000: The Automation Controller

Weidmüller’s u-control 2000: The Automation Controller

Weidmüller’s scalable engineering software, u-control 2000, adapts individually to your requirements. And, the u-control is powerful, compact and fully compatible with Weidmüller’s I/O system u-remote. This article looks at what makes u-control the heart of your automation.

Programmable logic controllers (PLCs) are one of the main components of any automated system. A typical control system has inputs, outputs, controllers (i.e., PLCs), and some type of human interaction with the system, a human machine interface (HMI), for example.

Read More



Latest Articles

  • NOARK’s Breakthrough in AI Data Centers: A Story of Speed, Strategy, and Execution

    May 19, 2026 In November 2025, NOARK Electric was presented with an opportunity that would test not only its capabilities, but its agility, coordination, and decision-making under pressure. A global technology and social media company—rapidly expanding its AI infrastructure—issued a request for quotation for pad-mounted transformers and switchboards. The scope was significant: a multi-million-dollar order tied to Read More…

  • State of the Data Center Boom 2026: Why Power Infrastructure Now Defines What Gets Built

    May 19, 2026 Data centers sit at the heart of the modern digital economy. Every AI query, cloud workload, streamed video, or online transaction depends on reliable, always-on infrastructure operating behind the scenes. As digital demand accelerates, data center development is expanding rapidly across North America, with the United States leading growth and Canada emerging Read More…