HEX Editor
Important Security Information

log4j Security Vulnerablities

The Apache Log4j Library contain a set of security vulnerabilityies

CVE-2021-45105, CVE-2021-44228.

Applicability to Hex Editor

Vector Embedded Products

Vector embedded software products for ECUs (e.g., MICROSAR) do not employ the Apache Log4j Library. Concerning the security of the embedded software, any exploit of this vulnerability is therefore equivalent to any other vulnerability at infrastructure level.

Vector Embedded Products related Tool Products & Tools

Vector provides Java-based development tools and helper tools used for the configuration/analysis of the embedded software. Vector Hex Editor uses Apache Log4j. Affected Product Versions are shown below. All newer Product Versions (as the latest stated Product Version) will not contain any version of Log4j affected by CVE-2021-45105 or CVE-2021-44228.

Please check the Apache Website for the latest information on workarounds and/or mitigations:

See also https://logging.apache.org/log4j/2.x/security.html.

Risk analysis

We assume that there is no significant increase of risk resulting from the usage of this tool since it is a client-only tool establishing an authenticated communication to the Vector Portal.

Recommended Actions

Only the Hex Editor Versions below are affected by this vulnerability. This issue will be fixed in future Service Packs, Updates or is already fixed via hotfix (Fix Version). Please update to one of the Fix Version mentioned in the description below when its available. Please contact your Vector contact to get the Fix Version in case you have not been notified by us yet.Please also replace all copies and installations of the affected Version on your side.

Please check this page or our Vector Portal for updates on availability for a Fix Version.

Product Version Specific Information

for CVE-2021-45105

v0.23.0 (affected)

  • A hotfix (v0.23.1) will be released in 01/2021
  • We recommend updating to new Version v0.23.1 or later Versions after availability

for CVE-2021-44228

v0.23.0 (affected)

  • A hotfix (v0.23.1) is released
  • We recommend updating to new Version v0.23.1 or later Versions