peter bassill · operator
$ cve CVE-2013-0625 JSON

CVE-2013-0625 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 93.8% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-09-07.

Description

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS93.76% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-287
On CISA KEVyes — remediate by 2022-09-07
Public exploityes
Published2013-01-09
Last modified2026-06-16

CISA KEV

NameAdobe ColdFusion Authentication Bypass Vulnerability
Added2022-03-07
Due2022-09-07
Vendor / productAdobe / ColdFusion
Ransomware usenone reported

Affected (4)

VendorProduct
adobecoldfusion
applemac os x
microsoftwindows
opengroupunix

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD