U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-45046

Change History

Initial Analysis by NIST 12/15/2021 11:07:35 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:*
     *cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:*
     *cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:*
     *cpe:2.3:a:apache:log4j:2.0:rc2:*:*:*:*:*:*
     *cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* versions from (including) 2.0.1 up to (including) 2.12.1
     *cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* versions from (including) 2.13.0 up to (excluding) 2.15.0
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:arubanetworks:silver_peak_orchestrator:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:intel:audio_development_kit:-:*:*:*:*:*:*:*
     *cpe:2.3:a:intel:datacenter_manager:-:*:*:*:*:*:*:*
     *cpe:2.3:a:intel:oneapi:-:*:*:*:*:eclipse:*:*
     *cpe:2.3:a:intel:secure_device_onboard:-:*:*:*:*:*:*:*
     *cpe:2.3:a:intel:system_debugger:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:netapp:brocade_san_navigator:-:*:*:*:*:*:*:*
     *cpe:2.3:a:netapp:cloud_insights_acquisition_unit:-:*:*:*:*:*:*:*
     *cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:*
     *cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:*
     *cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
     *cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*
     *cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:vmware_vsphere:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:siemens:capital:-:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:cosmos:-:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:*:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:-:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:4.0:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:4.1:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:4.2:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:5.0:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:desigo_consumption_control_advanced_reporting:5.1:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:desigo_consumption_control_info_center:5.0:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:desigo_consumption_control_info_center:5.1:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:e-car_operating_center:*:*:*:*:cloud:*:*:* versions up to (excluding) 2021-12-13
     *cpe:2.3:a:siemens:energyip_prepay:3.7:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:energyip_prepay:3.8:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:* versions from (including) 8.6.2j-398
     *cpe:2.3:a:siemens:head-end_system_universal_device_integration_system:-:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:industrial_edge_management:-:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_wincc:7.4:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:sipass_integrated:2.80:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:sipass_integrated:2.85:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:siveillance_command:*:*:*:*:*:*:*:* versions up to (including) 4.16.2.1
     *cpe:2.3:a:siemens:siveillance_control:*:*:*:*:pro:*:*:* versions up to (excluding) 2.1
     *cpe:2.3:a:siemens:siveillance_identity:1.5:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:siveillance_identity:1.6:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:siveillance_vantage:-:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:solid_edge_wiring_harness_design:-:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:* versions up to (excluding) 4.70
     *cpe:2.3:a:siemens:spectrum_power_4:4.70:-:*:*:*:*:*:*
     *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp7:*:*:*:*:*:*
     *cpe:2.3:a:siemens:spectrum_power_4:4.70:sp8:*:*:*:*:*:*
     *cpe:2.3:a:siemens:spectrum_power_7:-:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:teamcenter_suite:-:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:vesys:-:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:xpedition_enterprise_data_management:*:*:*:*:*:*:*:* versions from (including) 2.6 up to (including) 2.10
     *cpe:2.3:a:siemens:xpedition_package_integrator:*:*:*:*:*:*:*:* versions from (including) 2.6 up to (including) 2.10
     *cpe:2.3:o:siemens:dynamic_security_assessment:4.2:*:*:*:*:*:*:*
     *cpe:2.3:o:siemens:dynamic_security_assessment:4.3:*:*:*:*:*:*:*
     *cpe:2.3:o:siemens:dynamic_security_assessment:4.4:*:*:*:*:*:*:*
     *cpe:2.3:o:siemens:industrial_edge_management:-:*:*:*:*:*:*:*
     *cpe:2.3:o:siemens:industrial_edge_manangement_hub:-:*:*:*:*:*:*:*
     *cpe:2.3:o:siemens:logo\!_soft_comfort:-:*:*:*:*:*:*:*
     *cpe:2.3:o:siemens:mendix:-:*:*:*:*:*:*:*
     *cpe:2.3:o:siemens:mindsphere:*:*:*:*:cloud:*:*:* versions up to (excluding) 2021-12-11
     *cpe:2.3:o:siemens:nx:-:*:*:*:*:*:*:*
     *cpe:2.3:o:siemens:opcenter_intelligence:*:*:*:*:*:*:*:* versions from (including) 3.2
     *cpe:2.3:o:siemens:operation_scheduler:*:*:*:*:*:*:*:* versions from (including) 1.1.3
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
     *cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
     *cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
NIST (AV:N/AC:H/Au:N/C:N/I:N/A:P)
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Added CWE

								
							
							
						
NIST CWE-502
Changed Reference Type
http://www.openwall.com/lists/oss-security/2021/12/14/4 No Types Assigned
http://www.openwall.com/lists/oss-security/2021/12/14/4 Mailing List, Mitigation, Third Party Advisory
Changed Reference Type
https://logging.apache.org/log4j/2.x/security.html No Types Assigned
https://logging.apache.org/log4j/2.x/security.html Mitigation, Release Notes, Vendor Advisory
Changed Reference Type
https://www.cve.org/CVERecord?id=CVE-2021-44228 No Types Assigned
https://www.cve.org/CVERecord?id=CVE-2021-44228 Not Applicable
Changed Reference Type
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html No Types Assigned
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html Third Party Advisory