Vulnerabilities > Cisco > Secure Access Control System > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-05-02 CVE-2018-0253 Improper Input Validation vulnerability in Cisco Secure Access Control System
A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system.
network
low complexity
cisco CWE-20
critical
9.8
2018-03-08 CVE-2018-0147 Deserialization of Untrusted Data vulnerability in Cisco Secure Access Control System 5.2(0.3)
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device.
network
low complexity
cisco CWE-502
critical
9.8