Record summary

CVE-2023-26347 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 6, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: affected

VulnCheck, CVE ListThrough 2021.11affected

Nuclei templates

1
ProjectDiscoveryHIGHAdobe Coldfusion - Authentication BypassCVSS 7.5

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

Impact

Unauthenticated attackers can bypass access controls to access Adobe ColdFusion administration endpoints, potentially allowing full control over the ColdFusion server and access to sensitive application data.

Remediation

Upgrade to Adobe ColdFusion 2023.6 or 2021.12 or later versions that address this access control vulnerability.

WeaknessesCWE-284
Authorssalts
Template tagscve2023cveadobecoldfusionauth-bypassvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*
Shodan: http.component:"Adobe ColdFusion"
Shodan: http.component:"adobe coldfusion"
Shodan: http.title:"coldfusion administrator login"
Shodan: cpe:"cpe:2.3:a:adobe:coldfusion"
FOFA: app="Adobe-ColdFusion"
FOFA: app="adobe-coldfusion"
FOFA: title="coldfusion administrator login"
Google: intitle:"coldfusion administrator login"

Source: ProjectDiscovery

References

2