Vulnerability record · CVE-2013-0625 · published 9 January 2013
CVE-2013-0625: Adobe ColdFusion authentication bypass when no password is set
Adobe · Coldfusion
Adobe ColdFusion 9.0, 9.0.1 and 9.0.2 allow remote attackers to bypass authentication when a password is not configured, and possibly execute arbitrary code via unspecified vectors. The flaw was exploited in the wild in January 2013, and the record does not specify the exact request path or component involved.
Description
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, confirmed in-the-wild exploitation, KEV listing and near-maximum EPSS make this an urgent patch-or-isolate case.
What it is
Adobe ColdFusion 9.0, 9.0.1 and 9.0.2 allow remote attackers to bypass authentication when a password is not configured, and possibly execute arbitrary code via unspecified vectors. The flaw was exploited in the wild in January 2013, and the record does not specify the exact request path or component involved.
Impact
An unauthenticated remote attacker gains access that bypasses authentication and may be able to execute arbitrary code on the ColdFusion server. Successful exploitation can lead to full compromise of the host and any data it processes.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not identify the specific endpoint or interface used, only that the condition depends on a password not being configured.
Exploitation
CVE-2013-0625 is listed in CISA KEV (added 2022-03-07) and the description states it was exploited in the wild in January 2013; EPSS is 0.93797 (99.8th percentile), indicating very high predicted exploitation activity. No ransomware campaign use is documented in the record.
What to do
- Apply the vendor updates referenced in Adobe security advisory APSA13-01 and bulletin APSB13-03, or upgrade to a supported ColdFusion release.
- Ensure an administrative password is configured on all ColdFusion instances, since the flaw requires a password not to be set.
- Restrict network access to ColdFusion administrative and exposed services to trusted hosts only.
- If the affected 9.0.x versions cannot be patched or upgraded, isolate or retire the instance.
Detection
- Review ColdFusion server and web logs for unauthenticated requests to administrative or login endpoints that succeed without prior authentication.
- Audit ColdFusion configuration to confirm whether an administrator password is set on each instance.
- Monitor for unexpected process execution or child processes spawned by the ColdFusion service.
- Alert on exploitation attempts matching known ColdFusion authentication bypass patterns from threat intelligence feeds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-0625 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "Adobe ColdFusion Authentication Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.adobe.com/support/security/advisories/apsa13-01.html | Vendor Advisory |
| http://www.adobe.com/support/security/bulletins/apsb13-03.html | Not Applicable |
| http://www.securityfocus.com/bid/57164 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.adobe.com/support/security/advisories/apsa13-01.html | Vendor Advisory |
| http://www.adobe.com/support/security/bulletins/apsb13-03.html | Not Applicable |
| http://www.securityfocus.com/bid/57164 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0625 | US Government Resource |
Track CVE-2013-0625 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0625), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.