CVE-2018-0147
Cisco Secure Access Control System Java Deserialization Vulnerability
⚠ KEVEPSS 18.3%
Description
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
How to fix CVE-2018-0147
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2018-0147 being exploited?
Yes — CVE-2018-0147 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.