CVE-2013-0629 describes a critical vulnerability in Adobe ColdFusion versions 9.0, 9.0.1, 9.0.2, and 10, specifically when a password is not configured, allowing attackers to access restricted directories. This vulnerability carries a high CVSS score of 7.5, indicating a network-exploitable flaw with low attack complexity and high confidentiality impact. It has been actively exploited in the wild since January 2013, is listed in CISA's KEV catalog, and has garnered significant community discussion and media coverage, including a Metasploit module.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:* | ||
9.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:9.0.1:*:*:*:*:*:*:* | ||
9.0.2CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:9.0.2:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.