Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0147

Опубликовано: 08 мар. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:secure_access_control_system:5.2\(0.3\):*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.03003
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-20
CWE-502

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.

CVSS3: 9.8
fstec
почти 8 лет назад

Уязвимость программного средства управления доступом Cisco Secure Access Control System, связанная с восстановлением в памяти недостоверной структуры данных, позволяющая нарушителю выполнять произвольные команды с привилегиями root

EPSS

Процентиль: 86%
0.03003
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-20
CWE-502