Apache Log4j Vulnerability in Omada Controller - Updated on May 18, 2022 [Case Closed]

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Apache Log4j Vulnerability in Omada Controller - Updated on May 18, 2022 [Case Closed]

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
65 Reply
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-17 11:04:27

Dear @WirelessForEver,

 

WirelessForEver wrote

Will there be another release soon given that CVE-2021-45046 on Log4j 2.15.0 has been upgraded to a RCE?

https://www.lunasec.io/docs/blog/log4j-zero-day-severity-of-cve-2021-45046-increased/

 

Yes, I just updated this solution post with the official firmware for Omada Controller v4/v5.

Please kindly check the main body for details. Cheers!

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
2
2
#45
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-17 11:08:38

 

Fae wrote

Dear @WirelessForEver,

 

WirelessForEver wrote

Will there be another release soon given that CVE-2021-45046 on Log4j 2.15.0 has been upgraded to a RCE?

https://www.lunasec.io/docs/blog/log4j-zero-day-severity-of-cve-2021-45046-increased/

 

Yes, I just updated this solution post with the official firmware for Omada Controller v4/v5.

Please kindly check the main body for details. Cheers!

@Fae 

 

Perfect! I see that now!

 

FYI, you may want to update this part too given the increase in severity:

 

CVE-2021-45046: https://www.cve.org/CVERecord?id=CVE-2021-45046

Severity: Moderate

Base CVSS Score: 3.7 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

 

to 

 

CVE-2021-45046: https://www.cve.org/CVERecord?id=CVE-2021-45046

Severity: Critical

Base CVSS Score: 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)

1
1
#46
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-17 11:49:00

Dear @WirelessForEver,

 

WirelessForEver wrote

FYI, you may want to update this part too given the increase in severity:

 

CVE-2021-45046: https://www.cve.org/CVERecord?id=CVE-2021-45046

Severity: Moderate

Base CVSS Score: 3.7 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

 

to 

 

CVE-2021-45046: https://www.cve.org/CVERecord?id=CVE-2021-45046

Severity: Critical

Base CVSS Score: 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)

 

Thank you for your information. Updated now.

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
0
0
#47
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-17 12:42:21

Restore fails from 3.2.15 to 5.0.29 Windows.

 

Thanks guys. 

0
0
#48
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-17 14:46:51

@Fae First I want to give you a huge THANK YOU for being so responsive and forthcoming with information.  It's been such a relief.  I do have another follow-up question for you: my OC300 controller version is 4.3.5, and the firmware is indicating 1.1.0 build 20210406 Rel.58776.  Do you anticipate that I will be able to update directly to the latest patch when it is available?

0
0
#49
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-17 18:09:47

@Fae As the firmware of controllers has been behind for quite a while compared to software version (5.0.29 on Windows and 4.4.6 for both OC200/300 firmware), when can we expect the latest patches?

1
1
#50
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-17 20:49:51

@nullV Earlier in the thread Fae was saying mid- to late next week.

0
0
#51
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-18 17:40:48

@Fae 

 

I have OC200 with the foll. details:

Controller Version: 4.4.6

Model: OC200 1.0

Firmware Version: 1.9.3 Build 20210914 Rel.39903

 

Which patch should I be installing for this?

OC200(UN)_V1_1.14.1_20211213 (Beta) -- Built-in Omada Controller v5.0.21

OR

OC200(UN)_V1_1.2.5_Build 20211214 (Beta)

 

 

0
0
#52
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-18 21:49:59

@Fae 

 

Yet another critical vulnerability was found, requiring an upgrade to 2.17.0:

 

https://logging.apache.org/log4j/2.x/security.html

0
0
#53
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-19 02:03:37

@WirelessForEver  - Merry Christmas... Log4j is the gift that just keeps on giving!

1
1
#54