Insecure Deserialization Vulnerability in Cisco Secure Access Control System
CVE-2018-0147
Summary
A vulnerability exists in the Java deserialization process utilized by Cisco Secure Access Control System (ACS) versions prior to 5.8 patch 9. This flaw allows an unauthenticated, remote attacker to craft and send a serialized Java object, potentially leading to the execution of arbitrary commands with root privileges on the affected device. Exploiting this issue could compromise system integrity and grant attackers unauthorized access, making it crucial for users to apply necessary patches and updates.
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply updates per vendor instructions.
Affected Version(s)
Cisco Secure Access Control System Cisco Secure Access Control System
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved