← Vulnerability feed

Vulnerability record · CVE-2018-15381 · published 8 November 2018

CVE-2018-15381: Cisco Unity Express Java deserialization allows unauthenticated root command execution

Cisco · Unity Express

Cisco Unity Express deserializes user-supplied content insecurely, allowing a remote attacker to send a malicious serialized Java object to the Java RMI service. Because the flaw is reachable without authentication and yields root-level command execution, it is a severe pre-auth remote code execution issue for exposed CUE deployments.

9.8 CVSS 3.0 Critical EPSS 87% · top 0.3% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.0 base score, v2 10.0
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to the listening Java Remote Method Invocation (RMI) service. A successful exploit could allow the attacker to execute arbitrary commands on the device with root privileges.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable deserialization leading to root command execution, with a 9.8 CVSS score and very high EPSS probability, makes this an urgent patch-or-isolate case.

What it is

Cisco Unity Express deserializes user-supplied content insecurely, allowing a remote attacker to send a malicious serialized Java object to the Java RMI service. Because the flaw is reachable without authentication and yields root-level command execution, it is a severe pre-auth remote code execution issue for exposed CUE deployments.

Impact

An attacker gains arbitrary shell command execution with root privileges on the affected device, effectively full control of the appliance.

Attack surface

Reachable over the network via the listening Java RMI service; the CVSS vector shows no privileges required and no user interaction, so any host that can reach the RMI port can attempt exploitation.

Exploitation

Not listed in CISA KEV and no public exploit tags appear in the references, but EPSS is very high (0.87254, 99.7th percentile), indicating strong predicted likelihood of exploitation activity.

What to do

  • Apply the Cisco Unity Express fix from the vendor advisory cisco-sa-20181107-cue; patch is the first action.
  • Restrict network access to the Java RMI service so only trusted management hosts can reach it, and block it at perimeter and inter-segment boundaries.
  • If the RMI service is not required, disable it; otherwise isolate CUE systems in a dedicated management VLAN.
  • Monitor Cisco advisories for updated guidance and verify the installed CUE version against the fixed release.
  • Treat any internet-exposed CUE RMI endpoint as compromised until logs are reviewed.

Detection

  • Alert on unexpected inbound connections to the Java RMI port on Unity Express systems, especially from non-management networks.
  • Look for Java deserialization or RMI-related error and exception entries in CUE and host logs.
  • Monitor for unexpected child processes or shell activity spawned by the Java/RMI service.
  • Baseline normal RMI client sources and flag new or anomalous source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15381 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2013-1120Cisco unity express software cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the a…EPSS 1.2%6.7CVE-2019-15986Cisco unity express os command injection vulnerabilityA vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro…EPSS 0.40%5.0CVE-2005-4794Cisco application and content networking software vulnerabilityCisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a deni…EPSS 2.4%2.1CVE-2006-2166Cisco unity express software vulnerabilityUnspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integrat…EPSS 1.6%9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed

Source: NIST National Vulnerability Database (record CVE-2018-15381), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.