Cisco Secure Access Control System
cpe:2.3:a:cisco:secure_access_control_system:*:*:*:*:*:*:*
- < 5.8.0.32.9
This vulnerability is being actively exploited in the wild.
A vulnerability exists in Cisco Secure Access Control System (ACS) versions prior to 5.8 patch 9, allowing an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the affected device. This vulnerability arises from insecure deserialization of user-supplied content, which can be exploited by sending a crafted serialized Java object.
Exploitation of this vulnerability could lead to unauthorized execution of commands on the affected device with root privileges.
Cisco has released a cumulative patch in version 5.8.0.32.9 that addresses this vulnerability. This version can be downloaded from the Cisco Software Center. For guidance on obtaining the update, refer to the Cisco Security Vulnerability Policy.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.