CVE-2018-0147
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
CISA KEV
- Vendor
- Cisco
- Product
- Secure Access Control System (ACS)
- Due date
- 2022-04-15
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2018-0147
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.