CVE-2018-0147
Cisco Secure Access Control System Java Deserialization Vulnerability
CVSS
—
No CVSS
EPSS
18.2%
p97
KEV
YES
Mar 25, 2022
Exploit Today
79
0-100
Published: — · Last modified: —
Product
Cisco / Secure Access Control System (ACS)
Vulnerability
Cisco Secure Access Control System Java Deserialization Vulnerability
Added to KEV
Mar 25, 2022
Remediate by
Apr 15, 2022
Known ransomware use
No
Summary description
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2018-0147
No related CVEs by CWE or product.