Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-0147
HistoryMar 08, 2018 - 7:29 a.m.

Deserialization of untrusted data

2018-03-0807:29:00
PRIOn knowledge base
www.prio-n.com
1

9.7 High

AI Score

Confidence

High

0.023 Low

EPSS

Percentile

89.8%

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.

CPENameOperatorVersion
secure_access_control_systemeq5.20.3

9.7 High

AI Score

Confidence

High

0.023 Low

EPSS

Percentile

89.8%