EXPOSURES › CVE-2018-0147
CVE-2018-0147
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco ACS suffered an unpatched Java deserialization vulnerability allowing remote command execution, now on CISA's KEV list.
Cisco Secure Access Control System (ACS) contained a Java deserialization flaw enabling unauthenticated remote attackers to execute arbitrary commands. This unpatched vulnerability is now on CISA's KEV list, indicating active exploitation in the wild. DIB organizations must verify ACS patch levels and consider replacing unpatched ACS instances to prevent remote code execution and maintain compliance.
Shame score — A known Java deserialization vulnerability remained unpatched long enough to be added to CISA's KEV list, demonstrating negligence and exposing systems to active exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |