12-16-2021 06:07 AM
Officially ACS 5.8 is EOL but I guess that it's still in use by some organizations.
Or maybe it uses Log4j 1.x ?
12-16-2021 07:31 AM
I would ping TAC on this one.
Some links that may help:
Cisco Secure Access Control System 5.8 - Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
12-19-2021 07:20 PM - edited 12-20-2021 10:00 AM
Please review the info shared by Mike.
Cisco Event Response: Apache Log4j Java Logging Library Security Incident has FAQ. Specifically as of today, it mentions,
> Q: Which Cisco products are affected by this vulnerability?
Please see the Products section of the security advisory for the list of products affected by this vulnerability. At this time, almost all affected Cisco products have either been remediated or have a software update scheduled for release.
> Q: Will Cisco provide software updates for products that have reached the End of Support milestone?
At this time, Cisco is focused on providing software updates for currently supported products.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide