Vulnerability record · CVE-2018-15381 · published 8 November 2018
CVE-2018-15381: Cisco Unity Express Java deserialization allows unauthenticated root command execution
Cisco · Unity Express
Cisco Unity Express deserializes user-supplied content insecurely, allowing a remote attacker to send a malicious serialized Java object to the Java RMI service. Because the flaw is reachable without authentication and yields root-level command execution, it is a severe pre-auth remote code execution issue for exposed CUE deployments.
Description
A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to the listening Java Remote Method Invocation (RMI) service. A successful exploit could allow the attacker to execute arbitrary commands on the device with root privileges.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable deserialization leading to root command execution, with a 9.8 CVSS score and very high EPSS probability, makes this an urgent patch-or-isolate case.
What it is
Cisco Unity Express deserializes user-supplied content insecurely, allowing a remote attacker to send a malicious serialized Java object to the Java RMI service. Because the flaw is reachable without authentication and yields root-level command execution, it is a severe pre-auth remote code execution issue for exposed CUE deployments.
Impact
An attacker gains arbitrary shell command execution with root privileges on the affected device, effectively full control of the appliance.
Attack surface
Reachable over the network via the listening Java RMI service; the CVSS vector shows no privileges required and no user interaction, so any host that can reach the RMI port can attempt exploitation.
Exploitation
Not listed in CISA KEV and no public exploit tags appear in the references, but EPSS is very high (0.87254, 99.7th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply the Cisco Unity Express fix from the vendor advisory cisco-sa-20181107-cue; patch is the first action.
- Restrict network access to the Java RMI service so only trusted management hosts can reach it, and block it at perimeter and inter-segment boundaries.
- If the RMI service is not required, disable it; otherwise isolate CUE systems in a dedicated management VLAN.
- Monitor Cisco advisories for updated guidance and verify the installed CUE version against the fixed release.
- Treat any internet-exposed CUE RMI endpoint as compromised until logs are reviewed.
Detection
- Alert on unexpected inbound connections to the Java RMI port on Unity Express systems, especially from non-management networks.
- Look for Java deserialization or RMI-related error and exception entries in CUE and host logs.
- Monitor for unexpected child processes or shell activity spawned by the Java/RMI service.
- Baseline normal RMI client sources and flag new or anomalous source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/105876 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1042130 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-cue | Vendor Advisory |
| http://www.securityfocus.com/bid/105876 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1042130 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-cue | Vendor Advisory |
Track CVE-2018-15381 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-15381), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.