Vulnerability Name: | CVE-2013-0632 (CCN-81244) | ||||||||
Assigned: | 2012-12-18 | ||||||||
Published: | 2013-01-15 | ||||||||
Updated: | 2014-01-17 | ||||||||
Summary: | administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 8.3 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-0632 Source: CCN Type: Adobe Product Security Advisory APSA13-01 Security Advisory for ColdFusion Source: CONFIRM Type: Vendor Advisory http://www.adobe.com/support/security/advisories/apsa13-01.html Source: CONFIRM Type: Vendor Advisory http://www.adobe.com/support/security/bulletins/apsb13-03.html Source: EXPLOIT-DB Type: UNKNOWN 30210 Source: CCN Type: BID-57330 Adobe ColdFusion CVE-2013-0632 Authentication Bypass Vulnerability Source: XF Type: UNKNOWN coldfusion-controls-cve20130632-sec-bypass(81244) Source: CCN Type: NMAP Web site File http-adobe-coldfusion-apsa1301 Source: CCN Type: Packet Storm Security [04-10-2013] Adobe ColdFusion APSB13-03 Command Execution Source: CCN Type: Packet Storm Security [08-19-2013] Packet Storm Advisory 2013-0819-2 - Adobe ColdFusion 9 Administrative Login Bypass Source: CCN Type: Packet Storm Security [12-11-2013] Adobe ColdFusion 9 Administrative Login Bypass Source: CCN Type: CYBERSECURITY & INFRASTRUCTURE SECURITY AGENCY KNOWN EXPLOITED VULNERABILITIES CATALOG Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [04-10-2013] Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [08-21-2013] Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [12-11-2013] | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |