cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3175
Views
5
Helpful
6
Replies

Are ESA or SMA vulnerable with log4j vulnerability ?

Vinay babu
Level 1
Level 1

Are CES ESA or CES SMA vulnerable with log4j vulnerability ?

6 Replies 6

dmccabej
Cisco Employee
Cisco Employee

Hello,

 

ESA and SMA were confirmed not impacted. You can follow along with the advisory for any ongoing updates.

 

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd

 

Thanks!

-Dennis M.

What about the Cisco Secure Email Encryption Plugin for Outlook? I know that has relied on Java in the past. 

 

At one time yesterday I could find it on this advisory,, and now it is not there:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd

Last I heard we were working on confirming CRES/plug-in and some other integrations. Updates should be pushed to the advisory when available.

 

Thanks!

-Dennis M.

The Cisco Secure Email Encryption Add-in is currently listed under "Cloud Offerings" in the security advisory. As of the latest update, it is still under investigation.

Are on-prem Cisco ESA and SMA appliance vulnerable?  

No.
This is from the Dutch National Computer Security Center. They've got a pretty good list going with pointers to the source.
https://github.com/NCSC-NL/log4shell/tree/main/software
Cisco's page
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd