peter bassill · operator
$ cve CVE-2013-0632 JSON

CVE-2013-0632 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 93.6% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS93.6% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-276
On CISA KEVyes — remediate by 2022-03-24
Public exploityes
Published2013-01-17
Last modified2026-06-16

CISA KEV

NameAdobe ColdFusion Authentication Bypass Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productAdobe / ColdFusion
Ransomware usenone reported

Affected (1)

VendorProduct
adobecoldfusion

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD