CVE-2013-0632 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 93.6% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-03-24.
Description
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 93.6% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-276 |
| On CISA KEV | yes — remediate by 2022-03-24 |
| Public exploit | yes |
| Published | 2013-01-17 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Adobe ColdFusion Authentication Bypass Vulnerability |
|---|---|
| Added | 2022-03-03 |
| Due | 2022-03-24 |
| Vendor / product | Adobe / ColdFusion |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| adobe | coldfusion |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe ColdFusion 9 - Administrative Authentication Bypass (Metasploit) | 2013-12-11 |
| exploit-db | Adobe ColdFusion 9 - Administrative Authentication Bypass | 2013-08-21 |
| exploit-db | Adobe ColdFusion APSB13-03 - Remote Multiple Vulnerabilities (Metasploit) | 2013-04-10 |
References
- http://www.adobe.com/support/security/advisories/apsa13-01.html
- http://www.adobe.com/support/security/bulletins/apsb13-03.html
- http://www.exploit-db.com/exploits/30210
- http://www.adobe.com/support/security/advisories/apsa13-01.html
- http://www.adobe.com/support/security/bulletins/apsb13-03.html
- http://www.exploit-db.com/exploits/30210
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0632
→ the Explorer · watch your stack · NVD