Vulnerability record · CVE-2018-0147 · published 8 March 2018
CVE-2018-0147: Cisco Secure Access Control System Java deserialization RCE
Cisco · Secure Access Control System
Cisco Secure Access Control System (ACS) before release 5.8 patch 9 deserializes user-supplied content insecurely, allowing a crafted serialized Java object to trigger arbitrary command execution. The flaw is remotely reachable without authentication and yields root-level control of the ACS appliance, which is a core identity and access management component.
Description
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution as root on an identity management appliance, with confirmed exploitation per CISA KEV and high EPSS score.
What it is
Cisco Secure Access Control System (ACS) before release 5.8 patch 9 deserializes user-supplied content insecurely, allowing a crafted serialized Java object to trigger arbitrary command execution. The flaw is remotely reachable without authentication and yields root-level control of the ACS appliance, which is a core identity and access management component.
Impact
An unauthenticated attacker can execute arbitrary commands with root privileges on the affected device, leading to full compromise of the ACS host and any credentials or policy data it manages.
Attack surface
Reachable over the network via a crafted serialized Java object sent to the affected service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
CVE-2018-0147 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), and EPSS shows a 30-day exploitation probability of roughly 18% (97th percentile), indicating observed exploitation activity.
What to do
- Upgrade Cisco Secure Access Control System to release 5.8 patch 9 or later as directed by the vendor advisory.
- If ACS cannot be patched immediately, restrict network access to the ACS management and service interfaces to trusted hosts only.
- Monitor and block untrusted serialized Java object traffic at network boundaries where feasible.
- Retire or isolate end-of-life ACS deployments that cannot receive vendor fixes.
- Review ACS host integrity and credentials for signs of prior compromise before returning it to service.
Detection
- Inspect network and application logs for serialized Java object payloads or deserialization errors targeting ACS endpoints.
- Alert on unexpected child processes, shell execution, or outbound connections originating from the ACS host.
- Monitor for anomalous authentication or configuration changes on ACS following suspicious inbound requests.
- Correlate ACS host telemetry with known exploitation indicators and CISA KEV guidance for this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0147 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Cisco Secure Access Control System Java Deserialization Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103328 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040463 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-acs2 | Vendor Advisory |
| http://www.securityfocus.com/bid/103328 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040463 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-acs2 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0147 | US Government Resource |
Track CVE-2018-0147 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0147), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.