CVE-2013-0625 is a critical authentication bypass vulnerability affecting Adobe ColdFusion versions 9.0, 9.0.1, and 9.0.2, specifically when a password is not configured. This flaw allows remote attackers to bypass authentication and potentially execute arbitrary code, impacting various systems including those running on Apple and Microsoft platforms. The vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe risk due to its network-based attack vector, low attack complexity, and high potential for complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score is 100/100, further emphasizing its extreme severity. This CVE has been actively exploited in the wild since January 2013 and is listed in CISA's KEV catalog. While no Metasploit or Nuclei modules are directly listed, an ExploitDB entry (EDB-24946) references a Metasploit module for related vulnerabilities. The vulnerability has garnered significant community discussion and media coverage, highlighting its widespread impact and the urgency of patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:* | ||
9.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:9.0.1:*:*:*:*:*:*:* | ||
9.0.2CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:9.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.