| DaVinci Configurator 5 |
| Important Security Information |
The Apache Log4j Library contain a set of security vulnerabilities
Vector Embedded Products
Vector embedded software products for ECUs (e.g., MICROSAR) do not employ the Apache Log4j Library. Concerning the security of the embedded software, any exploit of this vulnerability is therefore equivalent to any other vulnerability at infrastructure level.
Vector Embedded Products related Tool Products & Tools
Vector provides Java-based development tools and helper tools used for the configuration/analysis of the embedded software. DaVinci Configurator 5 uses Apache Log4j. Affected Product Versions are shown below. All newer Product Versions (as the latest stated Product Version) will not contain any version of Log4j mentioned above.
Please check the Apache Website for the latest information on workarounds and/or mitigations:
We assume that there is no significant increase of risk resulting from the usage of this tool since no external interface is provided by the tool.
Only the DaVinci Configurator 5 Versions below are affected by this vulnerability. This issue will be fixed in future Service Packs, Updates or is already fixed via hotfix (Fix Version). Please update to one of the Fix Versions mentioned in the description below when its available. You can download the Fix Version from our Vector Download Site (www.vector.com -> Downloads -> Service Packs)
Please also replace all copies and installations of the affected Version on your side.
Please check this page or Vector Download Site for updates on availability for a Fix Version.
Release roadmap for the mentioned Versions can be found here:
portal.vector.com/de/web/davinci/release-roadmap/davinci-configurator-pro.
V5.24 and Service Packs as mentioned here (affected)
for CVE-2021-45046 and CVE-2021-44228
for CVE-2021-45105
v5.17 – v5.23 and Service Packs as mentioned here (affected)
for CVE-2021-45105, CVE-2021-45046, CVE-2021-44228
v5.11 – v5.16 and their Service Packs (affected)
for CVE-2021-45105, CVE-2021-45046, CVE-2021-44228
All Versions < v5.11 as well as Versions and Service Packs newer as the mentioned fix versions above (not affected)