Skip to content
COOEY

EXPOSURES › CVE-2018-0147

CVE-2018-0147

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-0147 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Cisco ACS suffered an unpatched Java deserialization vulnerability allowing remote command execution, now on CISA's KEV list.

Cisco Secure Access Control System (ACS) contained a Java deserialization flaw enabling unauthenticated remote attackers to execute arbitrary commands. This unpatched vulnerability is now on CISA's KEV list, indicating active exploitation in the wild. DIB organizations must verify ACS patch levels and consider replacing unpatched ACS instances to prevent remote code execution and maintain compliance.

Shame score — A known Java deserialization vulnerability remained unpatched long enough to be added to CISA's KEV list, demonstrating negligence and exposing systems to active exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized