Apache Log4j Vulnerability in Omada Controller - Updated on May 18, 2022 [Case Closed]

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Apache Log4j Vulnerability in Omada Controller - Updated on May 18, 2022 [Case Closed]

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
66 Reply
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-17 10:28:58

@Fae 

 

Will there be another release soon given that CVE-2021-45046 on Log4j 2.15.0 has been upgraded to a RCE?

https://www.lunasec.io/docs/blog/log4j-zero-day-severity-of-cve-2021-45046-increased/

  0  
  0  
#44
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-17 11:04:27

Dear @WirelessForEver,

 

WirelessForEver wrote

Will there be another release soon given that CVE-2021-45046 on Log4j 2.15.0 has been upgraded to a RCE?

https://www.lunasec.io/docs/blog/log4j-zero-day-severity-of-cve-2021-45046-increased/

 

Yes, I just updated this solution post with the official firmware for Omada Controller v4/v5.

Please kindly check the main body for details. Cheers!

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
  2  
  2  
#45
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-17 11:08:38

 

Fae wrote

Dear @WirelessForEver,

 

WirelessForEver wrote

Will there be another release soon given that CVE-2021-45046 on Log4j 2.15.0 has been upgraded to a RCE?

https://www.lunasec.io/docs/blog/log4j-zero-day-severity-of-cve-2021-45046-increased/

 

Yes, I just updated this solution post with the official firmware for Omada Controller v4/v5.

Please kindly check the main body for details. Cheers!

@Fae 

 

Perfect! I see that now!

 

FYI, you may want to update this part too given the increase in severity:

 

CVE-2021-45046: https://www.cve.org/CVERecord?id=CVE-2021-45046

Severity: Moderate

Base CVSS Score: 3.7 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

 

to 

 

CVE-2021-45046: https://www.cve.org/CVERecord?id=CVE-2021-45046

Severity: Critical

Base CVSS Score: 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)

  1  
  1  
#46
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-17 11:49:00

Dear @WirelessForEver,

 

WirelessForEver wrote

FYI, you may want to update this part too given the increase in severity:

 

CVE-2021-45046: https://www.cve.org/CVERecord?id=CVE-2021-45046

Severity: Moderate

Base CVSS Score: 3.7 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

 

to 

 

CVE-2021-45046: https://www.cve.org/CVERecord?id=CVE-2021-45046

Severity: Critical

Base CVSS Score: 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)

 

Thank you for your information. Updated now.

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#47
Options
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-17 12:42:21

Restore fails from 3.2.15 to 5.0.29 Windows.

 

Thanks guys. 

  0  
  0  
#48
Options
Re:[Solution] Apache Log4j Vulnerability in Omada Controller
2021-12-17 14:46:51

@Fae First I want to give you a huge THANK YOU for being so responsive and forthcoming with information.  It's been such a relief.  I do have another follow-up question for you: my OC300 controller version is 4.3.5, and the firmware is indicating 1.1.0 build 20210406 Rel.58776.  Do you anticipate that I will be able to update directly to the latest patch when it is available?

  0  
  0  
#49
Options
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-17 18:09:47

@Fae As the firmware of controllers has been behind for quite a while compared to software version (5.0.29 on Windows and 4.4.6 for both OC200/300 firmware), when can we expect the latest patches?

  1  
  1  
#50
Options
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-17 20:49:51

@nullV Earlier in the thread Fae was saying mid- to late next week.

  0  
  0  
#51
Options
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-18 17:40:48

@Fae 

 

I have OC200 with the foll. details:

Controller Version: 4.4.6

Model: OC200 1.0

Firmware Version: 1.9.3 Build 20210914 Rel.39903

 

Which patch should I be installing for this?

OC200(UN)_V1_1.14.1_20211213 (Beta) -- Built-in Omada Controller v5.0.21

OR

OC200(UN)_V1_1.2.5_Build 20211214 (Beta)

 

 

  0  
  0  
#52
Options
Re:Apache Log4j Vulnerability in Omada Controller - Updated on 17 December 2021
2021-12-18 21:49:59

@Fae 

 

Yet another critical vulnerability was found, requiring an upgrade to 2.17.0:

 

https://logging.apache.org/log4j/2.x/security.html

  0  
  0  
#53
Options