CVE-2018-15958 is a critical deserialization of untrusted data vulnerability affecting Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier. This flaw allows an unauthenticated attacker to achieve arbitrary code execution with high impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available, the vulnerability has garnered some community discussion and media coverage, indicating awareness. Despite its high CVSS score of 9.8 and FAUCET Risk Score of 96/100, it is not listed in CISA's KEV catalog and is currently considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:-:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update1:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update10:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update11:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.