CVE-2013-0629highunder attack

CVE-2013-0629

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.5epss 66%
from disclosure to weapon91 days
Published on NVDJan 9
1st PoC+91d
CISA KEV+3344d
exploitation probability
66%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-09-07

Apply updates per vendor instructions.

In short

Adobe ColdFusion versions 9.0 through 10 can be accessed without proper authentication when no password is set, allowing attackers to view and manipulate restricted directories and sensitive data.

Technical detail

ColdFusion 9.0, 9.0.1, 9.0.2, and 10 fail to enforce authentication on restricted directories when administrator password is not configured, enabling unauthenticated directory traversal and access to sensitive resources. This vulnerability was actively exploited in the wild during January 2013.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.