Skip to main content

Milestone Security Advisory

000003587 Information about Spring4Shell (CVE-2022-22965)

Last Updated: 1 minute read
LanguageEnglish

Spring4Shell (CVE-2022-22965) is the name of a zero-day vulnerability in the Spring Framework (a popular Java framework) involving a critical-severity remote code execution issue, on web applications using the Spring Framework, under certain conditions. 

Our VMS software is not using the Spring Framework nor is it using any Java software, so the XProtect VMS, including the Mobile and Web Client, is not impacted by this vulnerability. We have never used Java and the Spring Framework, so our previous versions are not impacted either. The Spring Framework was also not detected on any Husky series. 

The PSIRT team continues to monitor the situation and will issue an update if there are any new discoveries.  

Article Number

000004016