CVE-2018-0147
Description
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.
In plain language
AI Act nowIf you run Cisco Secure Access Control System (ACS) versions earlier than 5.8 patch 9, a remote attacker could send a special message and get full root command execution without logging in.
CVE-2018-0147 is an unauthenticated remote code execution issue in Cisco Secure Access Control System (ACS) caused by insecure Java deserialization of attacker-supplied data, enabling arbitrary command execution with root privileges; it is listed in CISA KEV (real-world exploited) for ACS and requires the vendor update.
What to do now
- Check whether your Cisco Secure Access Control System (ACS) is running and confirm it is earlier than 5.8 patch 9.
- Identify the exact Cisco ACS build/patch level your installation is on (from your system/admin interface or vendor-provided inventory).
- If it is earlier than 5.8 patch 9, plan an emergency update following Cisco’s advisory and upgrade guidance for the fixed release.
- Apply the vendor-recommended updates to reach Cisco Secure Access Control System (ACS) version 5.8 patch 9 or later.
- After updating, verify the service is functioning normally and that remote access to the affected interface is restricted as applicable in your environment.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-0147 and every CVE in our database. Create a free account — no credit card required.
Create Free Account