Security Notification - Update for Apache Log4j2 Issue

SECURITY NOTIFICATION - UPDATE FOR APACHE LOG4J2 ISSUE (CVE-2021-44228)

December 16, 2021

 

Dear Valued Partners:

Hikvision is actively following the recently disclosed security vulnerability in the opensource Apache “Log4j2" utility (CVE-2021-44228) that has been classified as “Critical” with a CVSS score of 10 and allows for Remote Code Execution with system-level privileges or sensitive information leak.

In addition to monitoring the threat landscape for attacks and developing customer protections, our security teams immediately launched an investigation upon learning of the vulnerability. Below is a specific analysis of our research results so far:

  1. Hikvision’s IPC, NVR, CVR, transmission and display products, access control products and alarm products are not affected by this vulnerability.
  2. HikCentral Professional, HikCentral Enterprise, Hik-Connect, Hik-ProConnect, iVMS4200 and iVMS-3000N are not affected by this vulnerability.

Hikvision will continue to actively monitor the development of this issue as it evolves and provide updates to you. Countermeasures are in place to provide layers of protection and increase situational awareness.

If you have further questions, please do not hesitate to contact us at security.usa@hikvision.com.

 

Sincerely,

Hikvision USA Inc.

Hikvision.com uses strictly necessary cookies and related technologies to enable the website to function. With your consent, we would also like to use cookies to observe and analyse traffic levels and other metrics / show you targeted advertising / show you advertising on the basis of your location / tailor our website's content. For more information on cookie practices please refer to our cookie policy.

 

Contact Us

Get a better browsing experience

You are using a web browser we don’t support. Please try one of the following options to have a better experience of our web content.