CVE-2018-0147 is a critical Java deserialization vulnerability in Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9. An unauthenticated, remote attacker can exploit this flaw by sending a crafted serialized Java object, leading to arbitrary command execution with root privileges on the affected device. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 99/100, this vulnerability poses a severe threat due to its network-based attack vector and low attack complexity. This CVE is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community attention with numerous discussions and media coverage, despite no public exploit code being readily available in common exploit databases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2\(0.3\)CPE matchmatch criteria | cpe:2.3:a:cisco:secure_access_control_system:5.2\(0.3\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.