CVE-2018-0147
Cisco Secure Access Control System Java Deserialization Vulnerability
CVSS
—
Sin CVSS
EPSS
18.2%
p97
KEV
SÍ
25 mar 2022
Exploit Today
79
0-100
Publicado: — · Última mod.: —
Producto
Cisco / Secure Access Control System (ACS)
Vulnerabilidad
Cisco Secure Access Control System Java Deserialization Vulnerability
Añadido a KEV
25 mar 2022
Remediar antes de
15 abr 2022
Uso conocido en ransomware
No
Descripción resumida
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
Acción requerida
Apply updates per vendor instructions.
Notas
https://nvd.nist.gov/vuln/detail/CVE-2018-0147
Sin CVEs relacionados por CWE o producto.