Is my Daktronics Product or System impacted by the CVE-2021-44228 or Log4Shell vulnerability?

Topic

There is a widespread technology vulnerability (CVE-2021-44228 or Log4Shell) affecting many software and hardware systems.  This article breaks down Daktronics products that might be impacted.  

Environment

  • Product:
  • Component: CVE-2021-44228 or Log4Shell
  • Control System: Daktronics

Steps

Log4J Vulnerability

 

Vulnerable 

Under Investigation 

Not Vulnerable

All Sport Pro  X
Data Vision Software (DVS)  X
Daktronics Web Player- DWP-1000  X
Daktronics Media Player - DMP (any series)  X
Dynamic Messaging System (DMS)  X
Dynamic Messaging System- DMS Core Player  (P10)  X
Dynamic Messaging System- DMS Player hardware (AMP-R200, AMP-R400, AMP-R800, AMP-SM100, AMP-SE100, AMP-SM200, AMP-SM400)  X
IBoot- Dataprobe IBoot devices (A-3257,3256,2270,2269,1978)  X
Outdoor Smartlink Devices (A-3189335,3128, 3416, 3418,3707,3708,3709)  X
Routers- Cisco Meraki Z3/Z3C Routers (A-4036028)   X
Routers-Cisco Z1 Routers (A-3665)  X
Routers- Sierra Wireless RV50X/RV50 (A-3350704)  X
Show Control System (SCS)  X
Vanguard  X
Venus 1500  X

Venus Control Suite (VCS) 

 

 

X

Video Image Processors (VIP-5060/VIP-5160/VIP-4060)  X
Webcam- Mobotix  (A-2242, A-3127,A-3719)  X

Details: 

Reference individual venders for their statements.  This includes routers, power utilities, webcams, etc. 
DMS Web Player: Not present in our codebase, but awaiting confirmation from LG re: webOS platform.
DVS has one microservice that uses Log4j, but it uses a version that is not impacted.
DWP-1000: Not present in our codebase, but awaiting confirmation from LG re: webOS platform.
VCS is developed in .NET.
 

KB ID: 000025337


DISCLAIMER: Use of this content may void the equipment warranty, please read the disclaimer prior to performing any service of the equipment.

DAKTRONICS DOES NOT PROMISE THAT THE CONTENT PROVIDED HEREIN IS ERROR-FREE OR THAT ANY DEFECTS WILL BE CORRECTED, OR THAT YOUR USE OF THE CONTENT WILL PROVIDE SPECIFIC RESULTS. THE CONTENT IS DELIVERED ON AN "AS-IS" AND "AS-AVAILABLE" BASIS. ALL INFORMATION PROVIDED IN THIS ARTICLE IS SUBJECT TO CHANGE WITHOUT NOTICE. DAKTRONICS DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING ANY WARRANTIES OF ACCURACY, NON-INFRINGEMENT, MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. DAKTRONICS DISCLAIMS ANY AND ALL LIABILITY FOR THE ACTS, OMISSIONS AND CONDUCT OF YOU OR ANY THIRD PARTIES IN CONNECTION WITH OR RELATED TO YOUR USE OF THE CONTENT. ADJUSTMENT, REPAIR, OR SERVICE OF THE EQUIPMENT BY ANYONE OTHER THAN DAKTRONICS OR ITS AUTHORIZED REPAIR AGENTS MAY VOID THE EQUIPMENT WARRANTY. YOU ASSUME TOTAL RESPONSIBILITY FOR YOUR USE OF THE CONTENT AND ANY LINKED CONTENT. YOUR SOLE REMEDY AGAINST DAKTRONICS FOR DISSATISFACTION WITH THE CONTENT IS TO STOP USING THE CONTENT. THIS LIMITATION OF RELIEF IS A PART OF THE BARGAIN BETWEEN THE PARTIES.

The above disclaimer applies to any property damage, equipment failure, liability, infringement, or personal injury claim arising out of or in any way related to your use or application of the content, whether such claim is for breach of contract, tort, negligence or any other cause of action.