🛡 CVE-2018-0147
Cisco Secure Access Control System Java Deserialization Vulnerability
Cisco Secure Access Control System (ACS) CWE-20
Ransomware use
—
CISA KEV
EPSS
18.3%
Elevated · 97th pct
Added to KEV
2022-03-25
CISA
Remediate by
2022-04-15
⚠ OVERDUE
CWE
CWE-20
weakness
📈 EPSS exploit probability
18.3%
FIRST EPSS — 30-day probability of exploitation in the wild · band Elevated · higher than 97% of all scored CVEs
⚠ KEV remediation overdue
CISA required federal remediation by 2022-04-15. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.
📄 Description
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserializati
🔗 External references & OSINT
🔄 Internal pivots & actions
🛡 Add to case
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron