Executive brief
A Java deserialization vulnerability in Cisco Secure Access Control System (ACS) allows an unauthenticated, remote attacker to execute arbitrary commands with root privileges. The flaw exists due to insecure deserialization of user-supplied content when processing crafted serialized Java objects.
Affected products
- Cisco Secure Access Control System (ACS) Prior to 5.8 patch 9
Timeline
- 2018-03-07: advisory: Cisco published the initial security advisory.
- 2018-03-08: disclosed: NVD published the CVE entry.
- 2022-03-25: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
- 2022-03-25: exploited: Vulnerability reported as exploited in the wild.