<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Could ACS 5.8 be vulnerable to Log4j vulnerability  ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/could-acs-5-8-be-vulnerable-to-log4j-vulnerability/m-p/4521340#M571823</link>
    <description>&lt;P&gt;Please review the info shared by Mike.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tools.cisco.com/security/center/resources/prod_svc_info_log4j.html" target="_self"&gt;Cisco Event Response: Apache Log4j Java Logging Library Security Incident&lt;/A&gt;&amp;nbsp;has FAQ. Specifically as of today, it mentions,&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Q: Which Cisco products are affected by this vulnerability?&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Please see the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd#vp" target="_blank"&gt;Products&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;section of the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd" target="_blank"&gt;security advisory&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;for the list of products affected by this vulnerability. At this time, almost all affected Cisco products have either been remediated or have a software update scheduled for release.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Q: Will Cisco provide software updates for products that have reached the End of Support milestone?&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;At this time, Cisco is focused on providing software updates for currently supported products.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Dec 2021 18:00:50 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2021-12-20T18:00:50Z</dc:date>
    <item>
      <title>Could ACS 5.8 be vulnerable to Log4j vulnerability  ?</title>
      <link>https://community.cisco.com/t5/network-access-control/could-acs-5-8-be-vulnerable-to-log4j-vulnerability/m-p/4519893#M571741</link>
      <description>&lt;P&gt;Officially ACS 5.8 is&amp;nbsp; EOL but I guess that it's still in use by some organizations.&lt;/P&gt;&lt;P&gt;Or maybe it uses Log4j 1.x ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 14:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/could-acs-5-8-be-vulnerable-to-log4j-vulnerability/m-p/4519893#M571741</guid>
      <dc:creator>Lars.J.Nilsson</dc:creator>
      <dc:date>2021-12-16T14:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Could ACS 5.8 be vulnerable to Log4j vulnerability  ?</title>
      <link>https://community.cisco.com/t5/network-access-control/could-acs-5-8-be-vulnerable-to-log4j-vulnerability/m-p/4519972#M571747</link>
      <description>&lt;P&gt;I would ping TAC on this one.&lt;/P&gt;
&lt;P&gt;Some links that may help:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/security/secure-access-control-system-5-8/model.html" target="_blank"&gt;Cisco Secure Access Control System 5.8 - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd" target="_blank"&gt;Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html" target="_blank"&gt;Cisco Talos Intelligence Group - Comprehensive Threat Intelligence: Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 15:31:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/could-acs-5-8-be-vulnerable-to-log4j-vulnerability/m-p/4519972#M571747</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-12-16T15:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: Could ACS 5.8 be vulnerable to Log4j vulnerability  ?</title>
      <link>https://community.cisco.com/t5/network-access-control/could-acs-5-8-be-vulnerable-to-log4j-vulnerability/m-p/4521340#M571823</link>
      <description>&lt;P&gt;Please review the info shared by Mike.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tools.cisco.com/security/center/resources/prod_svc_info_log4j.html" target="_self"&gt;Cisco Event Response: Apache Log4j Java Logging Library Security Incident&lt;/A&gt;&amp;nbsp;has FAQ. Specifically as of today, it mentions,&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Q: Which Cisco products are affected by this vulnerability?&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Please see the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd#vp" target="_blank"&gt;Products&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;section of the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd" target="_blank"&gt;security advisory&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;for the list of products affected by this vulnerability. At this time, almost all affected Cisco products have either been remediated or have a software update scheduled for release.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Q: Will Cisco provide software updates for products that have reached the End of Support milestone?&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;At this time, Cisco is focused on providing software updates for currently supported products.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 18:00:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/could-acs-5-8-be-vulnerable-to-log4j-vulnerability/m-p/4521340#M571823</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-12-20T18:00:50Z</dc:date>
    </item>
  </channel>
</rss>

