December 16, 2021
Dear Valued Partners:
Hikvision is actively following the recently disclosed security vulnerability in the opensource Apache “Log4j2" utility (CVE-2021-44228) that has been classified as “Critical” with a CVSS score of 10 and allows for Remote Code Execution with system-level privileges or sensitive information leak.
In addition to monitoring the threat landscape for attacks and developing customer protections, our security teams immediately launched an investigation upon learning of the vulnerability. Below is a specific analysis of our research results so far:
- Hikvision’s IPC, NVR, CVR, transmission and display products, access control products and alarm products are not affected by this vulnerability.
- HikCentral Professional, HikCentral Enterprise, Hik-Connect, Hik-ProConnect, iVMS4200 and iVMS-3000N are not affected by this vulnerability.
Hikvision will continue to actively monitor the development of this issue as it evolves and provide updates to you. Countermeasures are in place to provide layers of protection and increase situational awareness.
If you have further questions, please do not hesitate to contact us at security.usa@hikvision.com.
Sincerely,
Hikvision USA Inc.