claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2018-0147-cisco-secure-access-control-system-acs.log

CVE-2018-0147 — Cisco Secure Access Control System Java Deserialization Vulnerability

2022-03-25 • CISA Known Exploited Vulnerability


[event] A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

> AFFECTED SOFTWARE

Field Value
Vendor Cisco
Product Secure Access Control System (ACS)
CWE CWE-20
CVE ID CVE-2018-0147
Date Added 2022-03-25
Due Date 2022-04-15
Ransomware Campaign Unknown

> MITIGATION

Apply updates per vendor instructions.

Due Date: 2022-04-15

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:13 UTC