Skip to content
This repository has been archived by the owner on Jun 16, 2022. It is now read-only.

APC - PowerChute Business Edition #50

Closed
OS3DrNick opened this issue Dec 13, 2021 · 8 comments
Closed

APC - PowerChute Business Edition #50

OS3DrNick opened this issue Dec 13, 2021 · 8 comments
Labels
investigate Investigation required

Comments

@OS3DrNick
Copy link

OS3DrNick commented Dec 13, 2021

Not visible anything on their site yet:

C:\Program Files (x86)\APC\PowerChute Business Edition\agent\lib>dir | findstr log4j

10-12-2020 18:42 264,058 log4j-api-2.11.1.jar
10-12-2020 18:42 1,607,936 log4j-core-2.11.1.jar
10-12-2020 18:42 23,242 log4j-slf4j-impl-2.11.1.jar

PowerChute Business Edition - 10.0.2.301

@rkokkelk rkokkelk added the investigate Investigation required label Dec 13, 2021
@maertsen
Copy link
Collaborator

@OS3DrNick we would very much appreciate a PR. Let me know if that causes issues (time or otherwise).

@OS3DrNick
Copy link
Author

i hope its oke: #53

@martijngoorman
Copy link
Contributor

martijngoorman commented Dec 13, 2021

Also PowerChute Network Shutdown 4.2.0 is vulnerable. Uses 2.2
C:\Program Files\APC\PowerChute\ {group name} \lib

  • log4j-api-2.2.jar
  • log4j-core-2.2.jar

@OS3DrNick
Copy link
Author

if everything's goes correctly PR is updated with new info.

@maertsen
Copy link
Collaborator

thanks both!

@BassieZ
Copy link

BassieZ commented Dec 15, 2021

https://download.schneider-electric.com/files?p_Doc_Ref=SESB-2021-347-01
At least they are aware. No fix available yet

@MoweME
Copy link

MoweME commented Dec 20, 2021

On December 17, Apache updated the previously Low Severity CVE-2021-45046, to Critical
severity as the vulnerability now includes the potential for information leakage or remote code
execution, in addition to the previously known risk of denial of service. Apache released Log4j
versions 2.16.0 (for Java 8 or later) and 2.12.2 (for Java 7) to fix both CVE-2021-44228 and
CVE-2021-45046.
Source: https://download.schneider-electric.com/files?p_Doc_Ref=SESB-2021-347-01

About a week too late to notice the seriousness of the situation.
Is that how they want to talk their way out of this? APC could have thought of it itself....
Anyway, at least there will be an update soon...

@SequoiaDu
Copy link

Mitigation has been published for PCBE and network shutdown: https://www.se.com/ww/en/download/document/SESB-2021-347-01/

This issue was closed.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
investigate Investigation required
Projects
None yet
Development

No branches or pull requests

7 participants