Vulnerability CVE-2026-34480 remediation for nic_monitor in DX UIM
search cancel

Vulnerability CVE-2026-34480 remediation for nic_monitor in DX UIM

book

Article ID: 450928

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

A vulnerability scan (Nessus) may detect CVE-2026-34480 related to Apache Log4j on DX Unified Infrastructure Management (UIM) servers. This vulnerability pertains to an XMLLayout sanitization issue in Log4j versions 2.0-alpha1 through 2.25.3, which can result in malformed XML or logging exceptions.

Environment

  • DX UIM 23.4.6
  • nic_monitor probe versions 1.60 and earlier
  • Robot version 23.4.5 or higher (required for Java 21)
  • Java 21

Cause

The issue is caused by the third-party Apache Log4j library version installed with the nic_monitor probe.

Resolution

Upgrade the nic_monitor probe to version 2.00 or higher. This version utilizes Log4j 2.25.4, which remediates CVE-2026-34480.

  1. Ensure Java 21 is deployed on the target Robot.
  2. Verify the Robot is at version 23.4.5 or higher.
  3. Download nic_monitor 2.0 from the Nimsoft Archive.
  4. Review the nic_monitor Release Notes for additional configuration details.