cbcvebase.
CVE-2018-0253
published 2018-05-02

CVE-2018-0253: A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary…

PriorityP269critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.98%
93.4th percentile
A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. Commands executed by the attacker are processed at the targeted user's privilege level. The vulnerability is due to insufficient validation of the Action Message Format (AMF) protocol. An attacker could exploit this vulnerability by sending a crafted AMF message that contains malicious code to a targeted user. A successful exploit could allow the attacker to execute arbitrary commands on the ACS device. This vulnerability affects all releases of Cisco Secure ACS prior to Release 5.8 Patch 7. Cisco Bug IDs: CSCve69037.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscosecure
ciscosecure_access_control_system< 5.85.8
ciscosecure_access_control_system
ciscosecure_access_control_system

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted AMF (Action Message Format) protocol message sent to the ACS Report component; detect malformed/malicious AMF traffic targeting Cisco ACS web interface
  • Attack is unauthenticated and targets the ACS Report component via the web interface; monitor for unexpected unauthenticated access to the Cisco ACS web interface
  • If Active Directory is integrated with Cisco ACS, monitor for domain administrator credential theft following exploitation
  • ·All releases of Cisco Secure ACS prior to Release 5.8 Patch 7 are vulnerable; patch to 5.8 Patch 7 or later to remediate
  • ·There are no workarounds available for this vulnerability; software update is the only mitigation
  • ·Cisco Bug ID CSCve69037 tracks this vulnerability and can be used for vendor patch tracking

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.