Implications of Log4j Vulnerability for Operational Technology (OT) Networks
ID: 4f168e41-6f5f-57e4-b2cf-4808dda515a5
STIX ID: report--4f168e41-6f5f-57e4-b2cf-4808dda515a5
Feed Name: Dragos Blog
Dragos Intelligence describes CVE-2021-44228 (Log4j2) — a widely present Java logging library remote code execution vulnerability — noting observed attempted and successful exploitation in the wild and a takedown of an adversary domain. The advisory assesses high risk to Operational Technology/ICS due to Log4j ubiquity in both open-source and proprietary systems, explains JNDI/LDAP/RMI/DNS attack vectors and nested/obfuscated payloads, and provides mitigation steps (upgrade to Log4j 2.15.0 or disable lookups/remove JndiLookup) plus recommendations for active hunting and network-based detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
