← Vulnerability feed

Vulnerability record · CVE-2020-27131 · published 17 November 2020

CVE-2020-27131: Cisco Security Manager Java deserialization remote code execution

Cisco · Security Manager

Cisco Security Manager deserializes user-supplied content insecurely, allowing an unauthenticated remote attacker to send a crafted serialized Java object to a specific listener and execute arbitrary commands. The flaw is rated CVSS 9.8 critical, and Cisco has not released software updates that address it, so affected deployments remain exposed.

9.8 CVSS 3.1 Critical EPSS 88% · top 0.2% CWE-20 · Improper input validationCWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 10.0
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit these vulnerabilities by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of NT AUTHORITY\SYSTEM on the Windows target host. Cisco has not released software updates that address these vulnerabilities.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution as SYSTEM with no vendor patch and very high EPSS probability.

What it is

Cisco Security Manager deserializes user-supplied content insecurely, allowing an unauthenticated remote attacker to send a crafted serialized Java object to a specific listener and execute arbitrary commands. The flaw is rated CVSS 9.8 critical, and Cisco has not released software updates that address it, so affected deployments remain exposed.

Impact

An attacker gains arbitrary command execution on the Windows host with NT AUTHORITY\SYSTEM privileges, effectively full control of the Security Manager server.

Attack surface

Reachable over the network via a malicious serialized Java object sent to a specific listener; the CVSS vector shows no authentication (PR:N) and no user interaction (UI:N) required.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high at 0.877 (99.75th percentile), indicating strong likelihood of attempted exploitation.

What to do

  • Apply any Cisco software updates or workarounds once released; the advisory states no fixed release exists, so track the vendor advisory for changes.
  • Restrict network access to the affected listener and Security Manager management interfaces to trusted hosts only.
  • Segment or isolate Security Manager hosts so a compromised server cannot reach broader Windows infrastructure.
  • Monitor the Cisco advisory for interim mitigations and consider disabling or firewalling the vulnerable deserialization endpoint if not required.

Detection

  • Monitor network traffic to the Security Manager listener for Java serialization streams (magic bytes 0xACED0005) from untrusted sources.
  • Alert on unexpected child processes spawned by the Security Manager Java process, especially cmd.exe or PowerShell running as SYSTEM.
  • Review Windows event logs for service or process creation anomalies on Security Manager hosts.
  • Baseline normal connections to the listener and alert on new or unusual source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-27131 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-3036Ciscoworks common services memory buffer overflow vulnerabilityMultiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote at…EPSS 6.0%10.0CVE-2009-1161Ciscoworks common services path traversal vulnerabilityDirectory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Uni…EPSS 13%9.8CVE-2020-27125Cisco security manager improper input validation vulnerabilityA vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The …EPSS 1.8%9.8CVE-2019-12630Cisco Security Manager Java deserialization allows remote command executionCisco Security Manager deserializes user-supplied content insecurely, letting an unauthenticated remote attacker send a crafted serialized Java objec…EPSS 66%analysed9.1CVE-2020-27130Cisco Security Manager path traversal allows unauthenticated file downloadCisco Security Manager fails to properly validate directory traversal sequences in requests to the affected device. An unauthenticated remote attacke…EPSS 66%analysed9.1CVE-2019-1903Cisco security manager xml external entity (xxe) vulnerabilityA vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of servic…EPSS 2.2%6.8CVE-2014-3267Cisco security manager cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attackers to hijack the …EPSS 1.2%6.8CVE-2008-3820Cisco security manager vulnerabilityCisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2020-27131), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.