LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0147: Cisco Secure Access Control System Java Deserialization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)
9.8
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0147 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.

CVE-2018-0147 is a Java deserialization vulnerability in Cisco Secure Access Control System (ACS). An unauthenticated remote attacker could abuse insecure handling of user-supplied content to execute arbitrary commands on an affected device. Because ACS is used for access control, successful exploitation can put authentication and authorization infrastructure at risk. Confirm all product and fix details against the vendor advisory.

How it works

The weakness is tracked as CWE-20 (improper input validation) and centers on insecure Java deserialization. The affected software deserializes content supplied by a user without adequate validation. In this class of flaw, an attacker who can reach the vulnerable interface sends crafted serialized data. When the application deserializes that data, it can trigger unintended object creation and method execution, ultimately allowing arbitrary command execution on the device. The CISA summary states the vulnerability could allow an unauthenticated, remote attacker to execute arbitrary commands because of this insecure deserialization of user-supplied content. Exact request paths, payloads, or preconditions are not provided here; treat any public proof-of-concept material with caution and validate behavior only in controlled lab conditions against the vendor’s description.

Am I affected? How to find it in your systems

Cisco Secure Access Control System (ACS) is typically deployed as a centralized AAA (authentication, authorization, and accounting) platform in enterprise networks, often on dedicated appliances or servers that integrate with network devices, VPN gateways, and identity stores. Inventory efforts should focus on systems running ACS and any management or web interfaces exposed to users or networks.

How to remediate

Patch first. Apply the updates Cisco released for this vulnerability, following the vendor instructions referenced in the CISA required action. Confirm the exact fixed software versions, upgrade paths, and any prerequisite steps in the official Cisco advisory before changing production systems.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls suited to an unauthenticated remote command-execution risk on an access-control system.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to full compromise of the affected device and subsequent misuse of access-control infrastructure, which may enable broader network access or data exposure. Ransomware use is not documented for this CVE in the provided facts. If you suspect exploitation, follow your incident response process: isolate affected systems as appropriate, preserve logs and forensic images, rotate credentials and secrets that ACS held or issued, and assess downstream impact on authenticated services. You can run a free exposure scan of your email addresses against known breach data to check whether associated accounts appear in public breach corpora while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Secure Access Control System (ACS)
WeaknessCWE-20
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedMar 8, 2018
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities