Unrated severityCISA KEVNVD Advisory· Published Mar 8, 2018· Updated Jan 12, 2026
CVE-2018-0147
CVE-2018-0147
Description
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/103328mitrevdb-entryx_refsource_BID
- www.securitytracker.com/id/1040463mitrevdb-entryx_refsource_SECTRACK
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-acs2mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.