PT-2018-1126 · Cisco+1 · Cisco Secure Access Control System+1
Mikhail Klyuchnikov
+2
·
Published
2018-03-07
·
Updated
2025-10-28
·
CVE-2018-0147
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Secure Access Control System versions prior to 5.8 patch 9
Description
A vulnerability in Java deserialization used by the affected software could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The issue is due to insecure deserialization of user-supplied content. An attacker could exploit this by sending a crafted serialized Java object, potentially allowing the execution of arbitrary commands on the device with root privileges.
Recommendations
For versions prior to 5.8 patch 9, update to release 5.8 patch 9 or later to resolve the issue. As a temporary workaround, consider restricting access to the Java deserialization functionality to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Secure Access Control System
Java