CVE-2023-38205
KEVlargeSecurity Feature Bypass in Adobe ColdFusion Exposes Admin CFM/CFC Endpoints
CISA: Adobe ColdFusion Improper Access Control Vulnerability
CVE-2023-38205 is an improper access control flaw (CWE-284) in the administration interface of Adobe ColdFusion that results in a security feature bypass. It can be triggered over the network with no authentication and no user interaction, by sending requests directly to the ColdFusion administrative CFM and CFC endpoints. An attacker who exploits it gains unauthorized access to those admin endpoints, with the CVSS vector indicating high confidentiality impact (no direct integrity or availability impact). Any organization running an unpatched ColdFusion 2018 (Update 18 or earlier), 2021 (Update 8 or earlier), or 2023 (Update 2 or earlier) instance is affected, particularly where the admin endpoints are reachable from untrusted networks. The flaw is being actively exploited: it was added to the CISA KEV catalog on 2023-07-20, EPSS assigns a 99.7% probability of exploitation within 30 days, and related news describes an out-of-band Adobe patch for an actively exploited ColdFusion zero-day plus thousands of observed ColdFusion exploit attempts, with companion flaws (CVE-2023-38203, CVE-2023-29298) used to deploy web shells; no standalone public PoC is known, but the KEV listing confirms in-the-wild use.
What to do: Apply Adobe's July 2023 out-of-band updates by upgrading to ColdFusion 2018 Update 19, 2021 Update 9, and 2023 Update 3, or later. Until patched, restrict network access to the ColdFusion Administrator CFM/CFC endpoints (the standard /CFIDE/administrator area) and review servers for compromise indicators such as web shells, given the companion ColdFusion flaws were exploited to deploy web shells. As a CISA KEV entry, federal and other KEV-bound operators must apply the vendor mitigations or discontinue use of the product if mitigations are unavailable.
| Adobe ColdFusion | 2018 Update 18 and earlier |
| Adobe ColdFusion | 2021 Update 8 and earlier |
| Adobe ColdFusion | 2023 Update 2 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
- Affected
- Adobe ColdFusion
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N