CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: Apr 15, 2022
Description
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
EPSS — Exploit Probability
4.0%
Higher than 88.3% of all CVEs
Required Action
https://nvd.nist.gov/vuln/detail/CVE-2018-0147
Risk Assessment
ELEVATEDIn CISA KEV
Details
- Severity
- High
- EPSS
- 4.0%
- CISA KEV
- Yes
- Ransomware
- Unknown
- Articles
- 0
Timeline
Published
Mar 25, 2022
Added to KEV
Mar 25, 2022
Remediation Due
Apr 15, 2022