<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security: CVE-2021-44228 -&amp;gt; Log4j 2 Vulnerability in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521890#M1085951</link>
    <description>&lt;P&gt;Many of the things you are asking are clearly explained in the online help that's available in FDM or the FMD configuration guide.&lt;/P&gt;
&lt;P&gt;Please do your due diligence and at least check there before asking.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Dec 2021 03:27:47 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-12-21T03:27:47Z</dc:date>
    <item>
      <title>Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521614#M1085931</link>
      <description>&lt;P&gt;Dear i have ASA-5516X device and cisco has defind that this device can be infected with the new recent vulnerability log4shall&lt;/P&gt;&lt;P&gt;i they just release hotfix to be added on ASA ftd device !&lt;/P&gt;&lt;P&gt;the work around is how to apply this hotfix or patched on my device&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SO I HAVE 2 FTD devices (Cisco ASA5516-X Threat Defense) 1 running&amp;nbsp;&amp;nbsp;Version 6.6.1 (Build 91) and other one is&amp;nbsp;Cisco ASA5516-X Threat Defense (75) Version 6.2.2 (Build 81) so please i need to know how can we fix this exploit ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;im running these devices managed by FDM NOT FMC ? PLEASE NEED ADVICE URGENT AND WHATS THE STEPS TO DO FOR THIS ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;according to this link&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa46963" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa46963&lt;/A&gt;&amp;nbsp;they release hotfix and i need to know how to add it on my&amp;nbsp;Cisco ASA5516-X Threat Defense (75)&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 15:49:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521614#M1085931</guid>
      <dc:creator>amralrazzaz</dc:creator>
      <dc:date>2021-12-20T15:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521673#M1085937</link>
      <description>&lt;P&gt;You install hotfixes the same way you install other updates.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/hotfix/Firepower_Hotfix_Release_Notes/about-firepower-hotfixes.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/hotfix/Firepower_Hotfix_Release_Notes/about-firepower-hotfixes.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;As I explained in the other thread related to this topic, the 6.4.0 hotfix (&lt;SPAN style="color: #487b32; font-family: CiscoSans, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;Cisco_FTD_Hotfix_EP-6.4.0.14-9.sh.REL.tar&lt;/SPAN&gt;) only applies to Firepower 6.4.0.x software - not your 6.6.1 or 6.2.2 devices. Those are still pending the release of a hotfix as of 20 December 2021.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 16:17:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521673#M1085937</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-12-20T16:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521806#M1085947</link>
      <description>&lt;P&gt;i can see now that cisco release hotfix for 6.6.5 and what im currently using is&amp;nbsp;Cisco ASA5516-X Threat Defense (75) Version 6.6.1 (Build 91) and dunt know what do know ? actually i dont wanna go for upgrade ! dunt know if there ae any possible ways to keep this version and dunt know if the hotfix for 6.6.5 will be compatible with my version or what ?!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it just from FDM i can browse&amp;nbsp;&lt;SPAN&gt;Cisco_FTD_Upgrade-6.6.5-81.sh.REL.tar&amp;nbsp; via gui and then upgrade ? and thats it?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;is the&amp;nbsp; current configurations will be removed or shall get backup then restore again ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;need advice please???&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 00:31:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521806#M1085947</guid>
      <dc:creator>amralrazzaz</dc:creator>
      <dc:date>2021-12-21T00:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521860#M1085950</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you please give the steps to upgrade from 6.6.1 to 6.6.5 asn im already donwloaded&amp;nbsp;&lt;SPAN&gt;Cisco_FTD_Upgrade-6.6.5-81.sh.REL.tar and i just need to know if i have to install also boot image and tftp using and install asa from scratch or its just like browse from fdm gui browse the tar file and upgrade ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 00:25:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521860#M1085950</guid>
      <dc:creator>amralrazzaz</dc:creator>
      <dc:date>2021-12-21T00:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521890#M1085951</link>
      <description>&lt;P&gt;Many of the things you are asking are clearly explained in the online help that's available in FDM or the FMD configuration guide.&lt;/P&gt;
&lt;P&gt;Please do your due diligence and at least check there before asking.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 03:27:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4521890#M1085951</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-12-21T03:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522085#M1085955</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;im using Device is running Cisco ASA5516-X Threat Defense (75) Version 6.6.1 (Build 91) and need to upgrade to the steps on below:&lt;/P&gt;&lt;P&gt;update to 6.6.5&lt;BR /&gt;update to 6.6.5.1&lt;BR /&gt;install hotfix DA&lt;/P&gt;&lt;P&gt;Note: my ftd is running/managed&amp;nbsp; on firepower device manager ? so shall i use this&amp;nbsp;&lt;SPAN&gt;Cisco_FTD_Upgrade-6.6.5-81.sh.REL.tar for upload on device and upgrade !&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 11:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522085#M1085955</guid>
      <dc:creator>amralrazzaz</dc:creator>
      <dc:date>2021-12-21T11:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522111#M1085956</link>
      <description>&lt;P&gt;Each of those upgrades has its own file which is clearly named on the downloads page.&lt;/P&gt;
&lt;P&gt;Each one is installed the same way via FDM.&lt;/P&gt;
&lt;P&gt;Install then in the order listed.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 12:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522111#M1085956</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-12-21T12:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522185#M1085957</link>
      <description>&lt;P&gt;Dear i already installed the files in separated steps and now after hotfix has been installed and ftd reboot ? how do i make sure that hotfix has been installed ? is there any show commands to find this ?&lt;/P&gt;&lt;P&gt;my version now is :&lt;/P&gt;&lt;P&gt;Cisco Fire Linux OS v6.6.5 (build 13)&lt;BR /&gt;Cisco ASA5516-X Threat Defense v6.6.5.1 (build 15)&lt;/P&gt;&lt;P&gt;so need to know if hotfix already installed after i finished doing all steps!!!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 14:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522185#M1085957</guid>
      <dc:creator>amralrazzaz</dc:creator>
      <dc:date>2021-12-21T14:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522193#M1085958</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp; Dear i had check the hotfix version after installed and this what i got and is that refer to what i installed recently ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cisco_FTD_Hotfix_DA-6.6.5.2-4.sh.REL.tar&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;6.6.1-91&lt;BR /&gt;6.6.5-81&lt;BR /&gt;6.6.5.1-15&lt;BR /&gt;&lt;STRONG&gt;Hotfix_DA-4__856373902&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 14:48:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522193#M1085958</guid>
      <dc:creator>amralrazzaz</dc:creator>
      <dc:date>2021-12-21T14:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522317#M1085963</link>
      <description>&lt;P&gt;Read the release notes!&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/hotfix/Firepower_Hotfix_Release_Notes/about-firepower-hotfixes.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/hotfix/Firepower_Hotfix_Release_Notes/about-firepower-hotfixes.html&lt;/A&gt;&lt;/P&gt;
&lt;SECTION id="id_115266__d54e214" class="section"&gt;
&lt;H3 class="title sectiontitle"&gt;Verifying Hotfix Success&lt;/H3&gt;
&lt;P class="p"&gt;To verify that your hotfix installed successfully, access the Linux shell (also called expert mode) and run the following command:&lt;/P&gt;
&lt;P class="p"&gt;&lt;CODE class="ph codeph"&gt;cat /etc/sf/patch_history&lt;/CODE&gt;&lt;/P&gt;
&lt;P class="p"&gt;The system lists all successful major upgrades, patches, hotfixes, and pre-install packages since the appliance was freshly installed.&lt;/P&gt;
&lt;/SECTION&gt;</description>
      <pubDate>Tue, 21 Dec 2021 18:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522317#M1085963</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-12-21T18:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522320#M1085965</link>
      <description>&lt;P&gt;Yes, it is very helpful&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 18:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522320#M1085965</guid>
      <dc:creator>Md Sakib Hossain</dc:creator>
      <dc:date>2021-12-21T18:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522427#M1085970</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;okay for i can see the version 6.2.3 hotfix release and i need to ask you :&lt;BR /&gt;i currently run Cisco ASA5516-X Threat Defense v6.2.3.3 (build 76) so shall use the hotfix&lt;BR /&gt;file directly (Cisco_FTD_Hotfix_EM-6.2.3.18-13.sh.REL.tar) or i have to run this (Cisco_FTD_Patch-6.2.3.17-30.sh.REL.tar)&lt;BR /&gt;then running the hotfix after ?&lt;/P&gt;&lt;P&gt;also this is what u currently running now :&lt;BR /&gt;6.2.2-81&lt;BR /&gt;6.2.3-83&lt;BR /&gt;6.2.3.3-76&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Firepower Threat Defense Hotfix 6.2.3 EM&lt;BR /&gt;do not untar&lt;BR /&gt;Cisco_FTD_Hotfix_EM-6.2.3.18-13.sh.REL.tar&lt;BR /&gt;Advisories&lt;BR /&gt;20-Dec-2021&lt;BR /&gt;135.47 MB&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Firepower Threat Defense Patch 6.2.3.17&lt;BR /&gt;do not untar&lt;BR /&gt;Cisco_FTD_Patch-6.2.3.17-30.sh.REL.tar&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 00:10:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522427#M1085970</guid>
      <dc:creator>amralrazzaz</dc:creator>
      <dc:date>2021-12-22T00:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522457#M1085972</link>
      <description>&lt;P&gt;Upgrade to 6.2.3.17 first using Cisco_FTD_Patch-6.2.3.17-30.sh.REL.tar.&lt;/P&gt;
&lt;P&gt;After that is successful add the hotfix Cisco_FTD_Hotfix_EM-6.2.3.18-13.sh.REL.tar&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 03:31:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4522457#M1085972</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-12-22T03:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Security: CVE-2021-44228 -&gt; Log4j 2 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4523306#M1086009</link>
      <description>&lt;P&gt;This is key here people!!! I did not know about the patch_history.&lt;/P&gt;&lt;P&gt;The firmware version listed in the UI or even on the FXOS images scope will still show the old version!&lt;/P&gt;&lt;P&gt;I opened a TAC case because I did not know about the "patch_history" trick. You would think this would be in the UI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ended up verifying mine by running:&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:root@FTD:/" target="_blank"&gt;&lt;STRONG&gt;root@FTD:/#&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;find . -name log4j*&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;./ngfw/var/cisco/ngfwWebUi/tomcat/webapps/ROOT/WEB-INF/lib/log4j-core-2.16.jar&amp;nbsp; &lt;/STRONG&gt;&amp;lt;-- the core file will be 2.3 pre hotfix and 2.16 post hotfix&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 18:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-cve-2021-44228-gt-log4j-2-vulnerability/m-p/4523306#M1086009</guid>
      <dc:creator>bcoverstone</dc:creator>
      <dc:date>2021-12-23T18:35:26Z</dc:date>
    </item>
  </channel>
</rss>

