The vulnerability, tracked as CVE-2021-44228, is also known as “Log4Shell.” Apache Log4j V2, versions below 2.15.0 do not protect JNDI features (as used in configuration, log messages, and parameters) against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters could execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Siemens is currently investigating the vulnerability so it can determine which products are affected and it will continuously update its advisory as more information becomes available.Products affected to date by the vulnerability include:
- E-Car OC Cloud Application: All versions. The vulnerability is fixed on central cloud service starting Tuesday; no user actions necessary.
- EnergyIP Prepay: V3.7 and V3.8, specific mitigation information has been released for the customer projects with the request of immediate deployment.
- Industrial Edge Management App (IEM-App): All versions. Exposure to vulnerability is limited as IEM-App runs in IEM-OS and IEM-OS is not intended to be exposed to public Internet and should be operated in a protected environment.
- Industrial Edge Management OS (IEM-OS): All versions. Exposure to vulnerability is limited as IEM-OS is not intended to be exposed to public internet and should be operated in a protected environment.
- Industrial Edge Manangement Hub: All versions. Vulnerability fixed on central cloud service starting Tuesday.
- LOGO! Soft Comfort: All versions. Currently no remediation is available.
- Mendix Applications: All versions. Although the Mendix runtime itself is not vulnerable to this exploit, Siemens recommends to upgrade log4j-core to at least version 2.15.0 in case log4j-core is part of a project.
- Mindsphere Cloud Application: All versions. Vulnerability fixed on central cloud service starting Monday.
- Operation Scheduler: All versions at or above V1.1.3. Currently no remediation is available.
- SIGUARD DSA: V4.2, V4.3, V4.4. Adapt the client and computation node start-up batch scripts or shell scripts by adding – Dlog4j2.formatMsgNoLookups=true directly after the java statement. Adapt the application server start-up by adding – Dlog4j2.formatMsgNoLookups=true somewhere after the standalone.sh statement. Stop and restart the SIGUARD DSA processes.
- SIMATIC WinCC V7.4: All versions under V7.4 SP1. https://support.industry.siemens.com/cs/ww/en/ view/109746038.
- Siveillance Command: All versions at or above 4.16.2.1. Currently no remediation is available.
- Siveillance Control Pro: All versions. Hotfix available for versions at or above V2.1 (contact customer support).
- Siveillance Vantage: All versions,. Currently no remediation is available. Block incoming and outgoing connections between the system and the Internet.
Siemens identified the following specific workarounds and mitigations that customers can apply to reduce the risk:
- If the specific Siemens product (which is currently using Log4j versions at or above 2.10 and below 2.15.0 in its versions released so far) allows it: Set the parameter log4j2.formatMsgNoLookups to ‘true’. The two most common options to set this parameter in the Java Virtual Machine are: As cmdline parameter (‘-Dlog4j2.formatMsgNoLookups=true’) or as environment variable (‘LOG4J_FORMAT_MSG_NO_LOOKUPS=”true”’).
- If the specific Siemens product (which is currently using Log4j versions 2.0-beta9 to 2.10.0 in its versions released so far) allows it: Remove the JndiLookup class from the classpath: ’zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class’
- If the specific Siemens product (which is currently using Log4j versions at or above 2.7 and below 2.15.0 in its versions released so far) allows it: Modify all PatternLayout patterns to specify the message converter as ‘%m{nolookups}’ instead of just ‘%m’.
- If the specific Siemens product allows it: Update the Log4j component to 2.15.0 or later versions on the systems where the product is installed.
CVE-2021-44228 is the case number for the vulnerability, which has a CVSS v3.1 base score of 10.0.
As a general security measure, Siemens recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens’ operational guidelines for Industrial Security, and to follow the recommendations in the product manuals.
Click here for additional information on Industrial Security by Siemens.
The following are the descriptions of the affected products:
E-Car OC (E-Car Operation Center) is a cloud service that manages charging infrastructures for electric vehicles (EVs), both in domestic and public or semi-public areas.
EnergyIP applications enable utilities, retailers, DSO’s and market operators proven technology to meet the needs and requirements of the energy sector.
EnergyIP Prepay is an end-to-end solution for smart prepaid energy management. It features flexible tariff management, real-time rating and charging, convenient payment, and recharging options as well as intelligent energy consumption control features.
Geolus software is a geometry-based search engine for both single and multi-CAD environment PLM stakeholders who need to reduce/control part costs throughout the product lifecycle, manage engineering design knowledge and increase manufacturing efficiencies.
HES UDIS (Head-End System Universal Device Integration System) is an integrated solution for process- ing meter data and device events.
Industrial Edge Management (IEM) enables a centralized management of Siemens Industrial Edge Devices and Edge Applications. IEM is tailored to customer’s needs and is operated by the customer (on-premises).
LOGO! Soft Comfort is an engineering software to configure and program LOGO! BM (Base Module) devices.
Mendix is a high productivity app platform that enables you to build and continuously improve mobile and web applications at scale. The Mendix Platform is designed to accelerate enterprise app delivery across your entire application development lifecycle, from ideation to deployment and operations.
MindSphere is an industrial IoT as a service solution.
Operation Scheduler is a tool that enables security operators to intelligently perform routine tasks. It can be used to schedule maintenance tasks.
SIGUARD DSA is a model-based dynamic stability assessment tool for online control room use and offline operational planning purposes.
SIMATIC WinCC is a supervisory control and data acquisition (SCADA) system.
SiPass integrated is a powerful and extremely flexible access control system.
Siveillance Control Pro is a command and control solution, specifically designed to support security management at critical infrastructure sites such as ports, airports, oil and gas power generation and distribution, chemical and pharma industries, heavy industries and campus environments.
Siveillance Vantage is an innovative and advanced software solution for mission critical security command and control centers operating critical infrastructure applications.
Solid Edge is a portfolio of software tools that addresses various product development processes : 3D design, simulation, manufacturing and design management.
Spectrum Power provides basic components for SCADA, communications, and data modeling for con- trol and monitoring systems. Application suites can be added to optimize network and generation management for all areas of energy management.

