← Vulnerability feed

Vulnerability record · CVE-2018-0147 · published 8 March 2018

CVE-2018-0147: Cisco Secure Access Control System Java deserialization RCE

Cisco · Secure Access Control System

Cisco Secure Access Control System (ACS) before release 5.8 patch 9 deserializes user-supplied content insecurely, allowing a crafted serialized Java object to trigger arbitrary command execution. The flaw is remotely reachable without authentication and yields root-level control of the ACS appliance, which is a core identity and access management component.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 18% · top 2.9% CWE-20 · Improper input validationCWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 10.0
18%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution as root on an identity management appliance, with confirmed exploitation per CISA KEV and high EPSS score.

What it is

Cisco Secure Access Control System (ACS) before release 5.8 patch 9 deserializes user-supplied content insecurely, allowing a crafted serialized Java object to trigger arbitrary command execution. The flaw is remotely reachable without authentication and yields root-level control of the ACS appliance, which is a core identity and access management component.

Impact

An unauthenticated attacker can execute arbitrary commands with root privileges on the affected device, leading to full compromise of the ACS host and any credentials or policy data it manages.

Attack surface

Reachable over the network via a crafted serialized Java object sent to the affected service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

CVE-2018-0147 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), and EPSS shows a 30-day exploitation probability of roughly 18% (97th percentile), indicating observed exploitation activity.

What to do

  • Upgrade Cisco Secure Access Control System to release 5.8 patch 9 or later as directed by the vendor advisory.
  • If ACS cannot be patched immediately, restrict network access to the ACS management and service interfaces to trusted hosts only.
  • Monitor and block untrusted serialized Java object traffic at network boundaries where feasible.
  • Retire or isolate end-of-life ACS deployments that cannot receive vendor fixes.
  • Review ACS host integrity and credentials for signs of prior compromise before returning it to service.

Detection

  • Inspect network and application logs for serialized Java object payloads or deserialization errors targeting ACS endpoints.
  • Alert on unexpected child processes, shell execution, or outbound connections originating from the ACS host.
  • Monitor for anomalous authentication or configuration changes on ACS following suspicious inbound requests.
  • Correlate ACS host telemetry with known exploitation indicators and CISA KEV guidance for this CVE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-0147 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Cisco Secure Access Control System Java Deserialization Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0147 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-0648Cisco secure access control system permissions and access controls vulnerabilityThe RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements,…EPSS 5.9%10.0CVE-2014-0650Cisco secure access control system improper input validation vulnerabilityThe web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system co…EPSS 3.4%9.8CVE-2018-0253Cisco secure access control system improper input validation vulnerabilityA vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute ar…EPSS 6.8%9.0CVE-2014-0649Cisco secure access control system permissions and access controls vulnerabilityThe RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remot…EPSS 2.6%7.5CVE-2017-3841Cisco secure access control system information exposure vulnerabilityA vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sens…EPSS 2.4%6.8CVE-2013-3424Cisco secure access control system cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in Administration and View pages in Cisco Secure Access Control System (ACS) allows remote attackers …EPSS 1.2%6.8CVE-2013-1200Cisco secure access control system improper authentication vulnerabilitySession fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web sessions via unspecified vectors, ak…EPSS 1.2%6.8CVE-2013-1196Cisco application networking manager improper input validation vulnerabilityThe command-line interface in Cisco Secure Access Control System (ACS), Identity Services Engine Software, Context Directory Agent, Application Netwo…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2018-0147), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.