Vulnerability record · CVE-2013-0629 · published 9 January 2013
CVE-2013-0629: Adobe ColdFusion directory traversal when no password is set
Adobe · Coldfusion
Adobe ColdFusion 9.0 through 10 permits attackers to reach restricted directories when no password is configured, using unspecified vectors. The flaw was exploited in the wild in January 2013 and is listed in CISA's Known Exploited Vulnerabilities catalog, so unpatched, password-less deployments are at real risk.
Description
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityNetwork-reachable, unauthenticated, high confidentiality impact, confirmed in-the-wild exploitation and KEV listing, though it requires the password-less configuration precondition.
What it is
Adobe ColdFusion 9.0 through 10 permits attackers to reach restricted directories when no password is configured, using unspecified vectors. The flaw was exploited in the wild in January 2013 and is listed in CISA's Known Exploited Vulnerabilities catalog, so unpatched, password-less deployments are at real risk.
Impact
An attacker can read files and directories that should be restricted, exposing configuration data, credentials or application source. The CVSS vector shows high confidentiality impact with no integrity or availability effect.
Attack surface
Reachable over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). The precondition stated in the description is that the ColdFusion instance has no password configured.
Exploitation
Listed in CISA KEV since 2022-03-07 and described as exploited in the wild in January 2013; EPSS 30-day probability is 0.659 (99.2nd percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor update referenced in Adobe advisory APSA13-01 / bulletin APSB13-03, or upgrade to a supported ColdFusion release.
- Configure an administrator password on every ColdFusion instance so the password-less condition no longer exists.
- Restrict network access to ColdFusion administrative and internal directories to trusted hosts only.
- Audit ColdFusion deployments for exposed directories and remove or relocate sensitive files from web-reachable paths.
Detection
- Review ColdFusion web and access logs for requests to administrative or restricted directory paths from unexpected sources.
- Alert on ColdFusion instances responding to admin paths without an authentication challenge.
- Inventory ColdFusion hosts and flag any running 9.0, 9.0.1, 9.0.2 or 10 without a configured administrator password.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-0629 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "Adobe ColdFusion Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.adobe.com/support/security/advisories/apsa13-01.html | Vendor Advisory |
| http://www.adobe.com/support/security/bulletins/apsb13-03.html | Not Applicable |
| http://www.securityfocus.com/bid/57165 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.adobe.com/support/security/advisories/apsa13-01.html | Vendor Advisory |
| http://www.adobe.com/support/security/bulletins/apsb13-03.html | Not Applicable |
| http://www.securityfocus.com/bid/57165 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0629 | US Government Resource |
Track CVE-2013-0629 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0629), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.