cancel
Showing results for 
Search instead for 
Did you mean: 

[CVE-2021-44228] Apache Log4j2 RCE

dawoon_lee
New Contributor II

Hello.

Our customer is running a Ruckus SmartZone (sz-100) controller.
The version of the controller is 5.1.1.0.598.


The customer asked if the SmartZone has the following this security vulnerabilities.

** Vulnerability: [CVE-2021-44228] Apache Log4j2 RCE

Thank you for your valuable answers to the above questions.

93 REPLIES 93

grodog-prod
Contributor II

The KBA is now live in the Support Portal at https://support.ruckuswireless.com/articles/000012025 and it's linked in each of the KSP patches.

The KSP patches and the updated Security Bulletin v1.3 are now linked from the new Log4j - RUCKUS Technical Support Response Center at https://support.ruckuswireless.com/log4j-ruckus-technical-support-response-center

The delay you saw with the KSPs being published earlier and then pulled was because 1) the KBA with KSP instructions didn't synch properly, so we pulled everything down until it was available, and 2) the KSPs had to be regenerated due to technical issues within the compression process (they were downloading as the wrong file types in Chrome). 

Everything is now up-to-date and available.  As you have feedback, please continue to chime in here---TAC is monitoring the thread actively through @vineet_nejawala and other engineers.

Thank you for your patience and your feedback throughout this process, and happy patching!

Allan.

Allan T. Grohe Jr.
==
Knowledge Management Program Director
for RUCKUS Customer Services & Support

JTakaMT
New Contributor III

@allan_grohe I'm on macOS Monterey 12.1 and the native built-in archive utility seems to extract the zipped patch/ksp into 3 files (digital_sig.bin, signing_cert.pem and the *.ksp file) and the KSP would not upload (displayed invalid file). I unarchived it with Keka for macOS and it was just one file (the *.ksp) and it uploaded into the controller with no issues.  Just a possible FYI for others that may experience this using the macOS built-in archive utility to extract the file. 

belka
New Contributor

It's 11pm and me and a co-worker were about go nuts when we found your comment. The default decompressor no MacOS does indeed break the file apart into 3. When I tried decompressing it on Windows, it outputted only one KSP file. Thanks!

JTakaMT
New Contributor III

No problem! My post is old but I run into the same issue with the latest Ruckus SZ144 KSP patch 7/2025 as well and latest macOS 15.x, used Keka again. I let Ruckus Support know. They had at least one customer lined up in the queue that sounded like the same issue. 

@JTakaMT Same thing for me, thanks for dropping the tip!  Keka FTW!