Vulnerability record · CVE-2020-27131 · published 17 November 2020
CVE-2020-27131: Cisco Security Manager Java deserialization remote code execution
Cisco · Security Manager
Cisco Security Manager deserializes user-supplied content insecurely, allowing an unauthenticated remote attacker to send a crafted serialized Java object to a specific listener and execute arbitrary commands. The flaw is rated CVSS 9.8 critical, and Cisco has not released software updates that address it, so affected deployments remain exposed.
Description
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit these vulnerabilities by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of NT AUTHORITY\SYSTEM on the Windows target host. Cisco has not released software updates that address these vulnerabilities.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution as SYSTEM with no vendor patch and very high EPSS probability.
What it is
Cisco Security Manager deserializes user-supplied content insecurely, allowing an unauthenticated remote attacker to send a crafted serialized Java object to a specific listener and execute arbitrary commands. The flaw is rated CVSS 9.8 critical, and Cisco has not released software updates that address it, so affected deployments remain exposed.
Impact
An attacker gains arbitrary command execution on the Windows host with NT AUTHORITY\SYSTEM privileges, effectively full control of the Security Manager server.
Attack surface
Reachable over the network via a malicious serialized Java object sent to a specific listener; the CVSS vector shows no authentication (PR:N) and no user interaction (UI:N) required.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high at 0.877 (99.75th percentile), indicating strong likelihood of attempted exploitation.
What to do
- Apply any Cisco software updates or workarounds once released; the advisory states no fixed release exists, so track the vendor advisory for changes.
- Restrict network access to the affected listener and Security Manager management interfaces to trusted hosts only.
- Segment or isolate Security Manager hosts so a compromised server cannot reach broader Windows infrastructure.
- Monitor the Cisco advisory for interim mitigations and consider disabling or firewalling the vulnerable deserialization endpoint if not required.
Detection
- Monitor network traffic to the Security Manager listener for Java serialization streams (magic bytes 0xACED0005) from untrusted sources.
- Alert on unexpected child processes spawned by the Security Manager Java process, especially cmd.exe or PowerShell running as SYSTEM.
- Review Windows event logs for service or process creation anomalies on Security Manager hosts.
- Baseline normal connections to the listener and alert on new or unusual source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-27131 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-27131), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.