Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2018-0147

Cisco Secure Access Control System Java Deserialization Vulnerability

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

cat cve-2018-0147.json
Vendor
Cisco
Product
Secure Access Control System (ACS)
CVSS
9.8
EPSS (exploit probability)
18.3%
Status
kev
CISA patch-by (BOD 22-01)
Published

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

Added to CISA’s Known Exploited Vulnerabilities catalog on 2022-03-25. Required action per CISA: Apply updates per vendor instructions. Due date: 2022-04-15.

This is an auto-synced KEV catalog record pending a full 0dayNews write-up — see CISA’s KEV catalog and the NVD record linked above for primary sources.