CVE-2018-0147
Cisco Secure Access Control System
Published 8 Mar 2018 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 25 Mar 2022, with a remediation deadline of 15 Apr 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.
References
- www.securityfocus.com/bid/103328 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1040463 · Third Party Advisory, VDB Entry
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-acs2 · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0147 · US Government Resource