Junglewise Threat Intelligence

CVE-2018-0147: Cisco Secure Access Control System Java Deserialization Vulnerability

CVE-2018-0147 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Vendors: Cisco.

Executive brief

A Java deserialization vulnerability in Cisco Secure Access Control System (ACS) allows an unauthenticated, remote attacker to execute arbitrary commands with root privileges. The flaw exists due to insecure deserialization of user-supplied content when processing crafted serialized Java objects.

Affected products

  • Cisco Secure Access Control System (ACS) Prior to 5.8 patch 9

Timeline

  • 2018-03-07: advisory: Cisco published the initial security advisory.
  • 2018-03-08: disclosed: NVD published the CVE entry.
  • 2022-03-25: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
  • 2022-03-25: exploited: Vulnerability reported as exploited in the wild.