cancel
Showing results for 
Search instead for 
Did you mean: 

[CVE-2021-44228] Apache Log4j2 RCE

dawoon_lee
New Contributor II

Hello.

Our customer is running a Ruckus SmartZone (sz-100) controller.
The version of the controller is 5.1.1.0.598.


The customer asked if the SmartZone has the following this security vulnerabilities.

** Vulnerability: [CVE-2021-44228] Apache Log4j2 RCE

Thank you for your valuable answers to the above questions.

91 REPLIES 91

grodog-prod
Contributor II

The KBA is now live in the Support Portal at https://support.ruckuswireless.com/articles/000012025 and it's linked in each of the KSP patches.

The KSP patches and the updated Security Bulletin v1.3 are now linked from the new Log4j - RUCKUS Technical Support Response Center at https://support.ruckuswireless.com/log4j-ruckus-technical-support-response-center

The delay you saw with the KSPs being published earlier and then pulled was because 1) the KBA with KSP instructions didn't synch properly, so we pulled everything down until it was available, and 2) the KSPs had to be regenerated due to technical issues within the compression process (they were downloading as the wrong file types in Chrome). 

Everything is now up-to-date and available.  As you have feedback, please continue to chime in here---TAC is monitoring the thread actively through @vineet_nejawala and other engineers.

Thank you for your patience and your feedback throughout this process, and happy patching!

Allan.

Allan T. Grohe Jr.
==
Knowledge Management Program Director
for RUCKUS Customer Services & Support

JTakaMT
New Contributor III

@allan_grohe I'm on macOS Monterey 12.1 and the native built-in archive utility seems to extract the zipped patch/ksp into 3 files (digital_sig.bin, signing_cert.pem and the *.ksp file) and the KSP would not upload (displayed invalid file). I unarchived it with Keka for macOS and it was just one file (the *.ksp) and it uploaded into the controller with no issues.  Just a possible FYI for others that may experience this using the macOS built-in archive utility to extract the file. 

@JTakaMT Same thing for me, thanks for dropping the tip!  Keka FTW!

@JTakaMT Yes the patch that needs to be uploaded is only .ksp file. Thank you for sharing your inputs that would help others.

Best Regards

vineet

kristphr
New Contributor III

@JTakaMT thank you for this!