CVE-2023-38205 is an Improper Access Control vulnerability affecting Adobe ColdFusion versions 2018u18, 2021u8, and 2023u2 and earlier. This flaw allows an attacker to bypass security features and access administrative CFM and CFC endpoints without user interaction. With a CVSS score of 7.5 (High) and an EPSS score indicating high exploitability, the vulnerability poses a significant risk due to potential unauthorized access to sensitive administrative functions. This CVE is actively exploited in the wild, as confirmed by its presence in the KEV catalog and extensive media coverage, including warnings from CISA. While no Metasploit module exists, Nuclei templates are available, and community discussion is notably high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.