Is Mikrotik affected by log4j ?

Hello,
as many may know, there is currently a critical vulnerability floating around. Many vendors have already announced whether they are affected or not.
Unfortunately, Mikrotik has not yet commented on this. Does anyone know if Mikrotik is affected?

I saw this post by Normis on Twitter:
https://twitter.com/normis/status/1470665680785653768

Seems that MikroTik is not using Log4j.

It would be mandatory that this critical topic will be announced via official channel and not via a private twitter account :open_mouth:

When were you required to have java in order to run any of the mikrotik products?
Lets announce every critical exploit that MikroTik is not affected by.

MikroTik is not using Java anywhere in our products, nothing is affected.

Normis please confirm officially that MT products dont have the Omicron virus!

yes, it is mandatory to do so. on the main page and all future changelogs.
lol

Why does MikroTik have to officially announce every completely unrelated thing? MikroTik doesnt have Covid and also doesn’t have WIN32/CIH either.

Log4j is a JAVA problem.

even the atlassian stuff (docs, support) don’t seem to be affected
https://community.atlassian.com/t5/Trust-Security-articles/Atlassian-s-Response-to-Log4j-CVE-2021-44228/ba-p/1886598#M134

Thank god for that.

Nomis,

That’s an especially arrogant response representing a company that doesn’t exactly have a spectacular record for avoiding security vulnerabilities. Keep in mind, the second search result for “mikrotik log4j” reminds me that 300,000 mikrotik routers are a ticking timebomb from the 2018/2019 CVS fiasco.

In any case, to answer your question as to why it is important for Mikrotik to make a statement is simple. Each time one of these new zero day disclosures is announced, your customers have to break away from their day jobs and take inventory of their assets to see if they are impacted. Mikrotik is one of many assets that needs to be assessed very quickly. A simple definitive statement from Mikrotik stating that their devices are not impacted by the log4j vulnerability would allow me to quickly check one off the list and move to the next. You would serve your customers well by doing so and most major IT vendors have already done so.

Have a happy holiday.

Hello,

I fully agree with Chenevert on every point he mentions.

I assume many Mikrotik employees unfortunately have no insight in how larger operations work and how a simple, yet time sensible statement could have helped a lot of people to justify themselves towards their upper management or security auditors.

Is there any special mikrotik firewall rule to protect network from this vulnerability?

Do you think that this problem could be solved with firewall rule?
Please suggest something and than we wonder if your idea could be changed to the firewall rule/rules.

There are no 300’000 ticking time bomb routers. This is fake news spread by a company that sells some software to “protect your network”. Since you believe this clickbait, I am not surprised you also ask about Log4j.

Please follow Mikrotik security blog and it will contain all RELEVANT announcements regarding Mikrotik related vulnerabilities.