ZeroHour

CVE-2013-0625

KEVlarge

Authentication Bypass in Adobe ColdFusion Grants Admin Access

CISA: Adobe ColdFusion Authentication Bypass Vulnerability

CVSS
EPSS
94%p100
Published
KEV added
AI analysis

CVE-2013-0625 is an authentication bypass (CWE-255) in Adobe ColdFusion that lets an unauthorized, unauthenticated user gain administrative access to the ColdFusion Administrator. It is triggered by remote requests against vulnerable ColdFusion installations' administrative interfaces (the source data specifies no technical details beyond the bypass itself), and an attacker who succeeds can take administrative control of the ColdFusion server, which in practice can be leveraged to run arbitrary commands on the host. Organizations running legacy ColdFusion are affected, with CISA's 2022 alert citing versions 9.0, 9.0.1, 9.0.2, and 10, and internet-exposed admin endpoints being the highest-risk targets. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07 after observed threat-actor use, and EPSS assigns it a 93.8% probability of exploitation in the next 30 days.

What to do: Apply updates per vendor instructions — the applicable Adobe ColdFusion security hotfixes (APSB13-03 era) for 9.x/10, and ideally upgrade to a currently supported ColdFusion release since those versions are end-of-life. Until patched, restrict /CFIDE/administrator and related admin API paths to trusted networks and confirm authentication is enforced. Review web logs for unauthenticated access to admin endpoints and check for unexpected administrative changes or command execution on the host.

Affected
Adobe ColdFusion
Estimated exposure
large≈10,000–50,000 internet-exposed ColdFusion servers, a meaningful share still on legacy 9.x/10 releases (order-of-magnitude estimate) — Internet-wide scans (Shodan/Censys) routinely index tens of thousands of publicly reachable ColdFusion servers, and legacy 9.x/10 deployments were still common when CISA observed exploitation in March 2022.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
ColdFusion
Weakness
CWE-255

In the news