The Cyber Security Review | Friday, December 02, 2022
Exposure management company Tenable has announced the results of a telemetry study examining the scope and impact of the critical Log4j vulnerability, known as Log4Shell, in the months following its initial disclosure.
FREMONT, CA: The results of a telemetry analysis evaluating the extent and effects of the serious Log4j vulnerability, also known as Log4Shell, following its original disclosure have been released by exposure management company Tenable. According to the data collected from over 500 million tests, 72 per cent of organisations remain vulnerable to the Log4Shell vulnerability as of October 1, 2022.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The data demonstrates the difficulties in resolving legacy vulnerabilities, which are the main factor in most data breaches. Organisations worldwide rushed to assess their risk when Log4Shell was found in December 2021. They dramatically redirected resources and devoted tens of thousands of hours to identification and cleanup operations in the weeks after its publication.
According to Tenable telemetry, as of December 2021, one in ten assets, including a variety of servers, online apps, containers, and IoT devices, were vulnerable to Log4Shell. Data from October 2022 indicated improvements, with 2.5 per cent of assets being exposed. Even so, after complete remediation was achieved, Log4Shell recurrences were found in almost one-third (29 per cent) of these assets.
The Chief Security Officer of Tenable stated that full remediation is very tough to achieve for a vulnerability that is that prevalent, and it's vital to remember that vulnerability remediation is not a one-and-done operation.
While an organisation may have been remediated at some time, they are likely to encounter Log4Shell again and again as they have added new assets to their environments.
The fight to eradicate Log4Shell is continuous, and they must regularly check their environments for bugs and other vulnerabilities.
According to the statistics, 28 per cent of organisations worldwide had fully remedied Log4Shell, a 14-point improvement over May 2022. Furthermore, 53 per cent of companies were exposed to Log4j during the study's time frame, which emphasises the vulnerability of Log4j and the ongoing need for remediation even if full remediation has already been accomplished.
29 per cent of exposed assets have Log4Shell reintroduced after complete remediation. Some sectors are doing better than others, with engineering (45 per cent), legal (38 per cent), financial (35 per cent), non-profit (33 per cent) and government (30 per cent) topping the pack with the highest percentage of organisations entirely remedied.
According to the data, 28 per cent of the CISA-defined critical infrastructure organisations have finished their remediation. After Europe, the Middle East, and Africa (27 per cent), Asia-Pacific (25 per cent) and Latin America (21 per cent), nearly one-third of North American organisations (28 per cent) have fully remedied Log4j.
The highest percentage of organisations that have partially remedied is found in North America (90 per cent), followed by Europe, the Middle East, Africa (85 per cent), Asia-Pacific (85 per cent), and Latin America (81 per cent).
More in News