CVE-2013-0625
KEVlargeAuthentication Bypass in Adobe ColdFusion Grants Admin Access
CISA: Adobe ColdFusion Authentication Bypass Vulnerability
CVE-2013-0625 is an authentication bypass (CWE-255) in Adobe ColdFusion that lets an unauthorized, unauthenticated user gain administrative access to the ColdFusion Administrator. It is triggered by remote requests against vulnerable ColdFusion installations' administrative interfaces (the source data specifies no technical details beyond the bypass itself), and an attacker who succeeds can take administrative control of the ColdFusion server, which in practice can be leveraged to run arbitrary commands on the host. Organizations running legacy ColdFusion are affected, with CISA's 2022 alert citing versions 9.0, 9.0.1, 9.0.2, and 10, and internet-exposed admin endpoints being the highest-risk targets. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07 after observed threat-actor use, and EPSS assigns it a 93.8% probability of exploitation in the next 30 days.
What to do: Apply updates per vendor instructions — the applicable Adobe ColdFusion security hotfixes (APSB13-03 era) for 9.x/10, and ideally upgrade to a currently supported ColdFusion release since those versions are end-of-life. Until patched, restrict /CFIDE/administrator and related admin API paths to trusted networks and confirm authentication is enforced. Review web logs for unauthenticated access to admin endpoints and check for unexpected administrative changes or command execution on the host.
| Adobe ColdFusion | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
- Affected
- Adobe ColdFusion
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- ColdFusion
- Weakness
- CWE-255