CVE-2018-15381
A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 87.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to the listening Java Remote Method Invocation (RMI) service. A successful exploit could allow the attacker to execute arbitrary commands on the device with root privileges.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 87.25% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- cisco/unity express
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/105876Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042130Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-cueVendor Advisory
- http://www.securityfocus.com/bid/105876Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042130Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-cueVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.