CVE-2018-0147
published 2018-03-08CVE-2018-0147: A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote…
PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
18.55%
96.9th percentile
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_system | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is a crafted serialized Java object sent remotely to Cisco Secure Access Control System (ACS); inspect inbound traffic for Java serialized object magic bytes (0xACED0005) targeting ACS services ↗
- →No authentication is required to exploit; any unauthenticated remote connection delivering a serialized Java payload to ACS should be treated as suspicious ↗
- →Successful exploitation results in command execution with root privileges on the ACS device; monitor for unexpected root-level process spawning from ACS Java processes ↗
- ·Vulnerability affects Cisco Secure ACS versions prior to release 5.8 patch 9 only; patched versions are not affected ↗
- ·Cisco confirmed there are no workarounds available; patching is the only remediation ↗
- ·This CVE is listed in CISA KEV, indicating confirmed in-the-wild exploitation; treat all unpatched ACS instances as actively at risk ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2ccw-7gjg-m467: A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5
ghsa_unreviewed·2022-05-13
CVE-2018-0147 [CRITICAL] CWE-20 GHSA-2ccw-7gjg-m467: A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.
VulnCheck
Cisco Secure Access Control System Java Deserialization Vulnerability
vulncheck·2018·CVSS 9.8
CVE-2018-0147 [CRITICAL] CWE-20 Cisco Secure Access Control System Java Deserialization Vulnerability
Cisco Secure Access Control System Java Deserialization Vulnerability
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
Affected: Cisco Secure Access Control System (ACS)
Required Action: Apply updates per vendor instructions.
Exploitation References: https://decoded.avast.io/martinchlumecky/dirtymoe-5/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://securityaffairs.co/wordpress/139821/security/cisco-old-vulnerabilities-exploitation.html
Remediation Due: 2022-04-15
CISA
Cisco Secure Access Control System Java Deserialization Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2018-0147 [CRITICAL] CWE-20 Cisco Secure Access Control System Java Deserialization Vulnerability
Vulnerability: Cisco Secure Access Control System Java Deserialization Vulnerability
Affected: Cisco Secure Access Control System (ACS)
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0147
Remediation Due Date: 2022-04-15
Cisco
Cisco Secure Access Control System Java Deserialization Vulnerability
vendor_cisco·2018-03-08·CVSS 9.8
CVE-2018-0147 [CRITICAL] CWE-20 Cisco Secure Access Control System Java Deserialization Vulnerability
Cisco Secure Access Control System Java Deserialization Vulnerability
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device.
The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecuri
Cisco
Cisco Secure Access Control System Java Deserialization Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0147 Cisco Secure Access Control System Java Deserialization Vulnerability
CVE-2018-0147: Cisco Secure Access Control System Java Deserialization Vulnerability
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvh25988
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/103328http://www.securitytracker.com/id/1040463https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-acs2http://www.securityfocus.com/bid/103328http://www.securitytracker.com/id/1040463https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-acs2https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0147
2018-03-08
Published
2022-03-25
Added to CISA KEV
Exploited in the wild