CVE-2018-0147
Cisco Secure Access Control System Java Deserialization Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 18.21% probability · 97th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Weakness
- CWE-20, CWE-502
- Affected
- cisco/secure access control system
- Source
- psirt@cisco.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-0147
References
- http://www.securityfocus.com/bid/103328Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040463Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-acs2Vendor Advisory
- http://www.securityfocus.com/bid/103328Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040463Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-acs2Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0147US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.