10
CVE-2013-0632
- EPSS 93.69%
- Veröffentlicht 17.01.2013 00:55:01
- Zuletzt bearbeitet 21.04.2026 21:01:44
- Erkennungen
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version 9.0
Adobe ≫ Coldfusion Version 9.0.1
Adobe ≫ Coldfusion Version 9.0.2
Adobe ≫ Coldfusion Version 10.0
03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Adobe ColdFusion Authentication Bypass Vulnerability
SchwachstelleAn authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 93.69% | 0.998 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
http://www.adobe.com/support/security/advisories/apsa13-01.html
http://www.adobe.com/support/security/bulletins/apsb13-03.html
http://www.exploit-db.com/exploits/30210
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0632