CVE-2013-0629
Published · Updated
83Vexday Risk Score
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
ssvc Actcvss 7.5epss 66%
from disclosure to weapon91 days
Published on NVDJan 9
1st PoC+91d
CISA KEV+3344d
exploitation probability
66%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-09-07
Apply updates per vendor instructions.
In short
Adobe ColdFusion versions 9.0 through 10 can be accessed without proper authentication when no password is set, allowing attackers to view and manipulate restricted directories and sensitive data.
Technical detail
ColdFusion 9.0, 9.0.1, 9.0.2, and 10 fail to enforce authentication on restricted directories when administrator password is not configured, enabling unauthenticated directory traversal and access to sensitive resources. This vulnerability was actively exploited in the wild during January 2013.
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/24946⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.