← Back to CVE List
Vulnerability Intelligence Report
Adobe ColdFusion Authentication Bypass Vulnerability

CVE-2013-0632

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:93.69%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-276 ↗CWE-276 Incorrect Default Permissions

Affected Products & Versions

Vendor Product Affected Versions
adobe coldfusion 9.0, 9.0.1, 9.0.2, 10.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
93.691%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAdobe Systems Incorporated · Vendor · USA
Reserved2012-12-18T00:00:00
Published2013-01-17T00:00:00
Patch Date2013-01-11
Last Updated2025-10-22T00:05:44

LINK COPIED TO CLIPBOARD