Cyber Resilience

CVE-2013-0629

Adobe Coldfusion 10.0 … 9.0.2

CISA KEVActive ExploitationEUVD Exploited
Published
09 January 2013
Modified
21 April 2026
KEV Added
07 March 2022
Patch / advisory
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.66 99.2th percentile
Risk Priority 84 floored blend · peak EPSS

Summary

CVE-2013-0629 is a high-severity an unspecified weakness vulnerability in Adobe Coldfusion. Its CVSS base score is 7.5 (High).

Operationally, ranked in the top 0.8% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Adobe ColdFusion versions 9.0, 9.0.1, 9.0.2, and 10 are affected by CVE-2013-0629 when no password is configured for the installation. The flaw permits unauthorized access to restricted directories through unspecified vectors and carries a CVSS 3.1 score of 7.5 reflecting network attack vector, low complexity, and no required authentication or user interaction.

Unauthenticated remote attackers can exploit the condition to read files outside intended web-accessible paths. The vulnerability was observed being exploited in the wild in January 2013.

Adobe addressed the issue in security advisories APSA13-01 and APSB13-03, which provide mitigation guidance and link to the corresponding bulletin APSB13-03 for patch information.

EU & UK References

Vulnerability Data

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.

CWE(s)
KEV Date Added
07 March 2022

Related Threats

CVEs Like This One

CVE-2013-0631Same product: Adobe Coldfusionboth on KEV
CVE-2013-0625Same product: Adobe Coldfusionboth on KEV
CVE-2011-2462Same product: Apple Mac Os Xboth on KEV
CVE-2014-0496Same product: Apple Mac Os Xboth on KEV
CVE-2018-4990Same product: Apple Mac Os Xboth on KEV
CVE-2015-0310Same product: Apple Mac Os Xboth on KEV
CVE-2014-9163Same product: Apple Mac Os Xboth on KEV
CVE-2010-2883Same product: Microsoft Windowsboth on KEV
CVE-2020-9715Same product: Microsoft Windowsboth on KEV
CVE-2023-26369Same product: Microsoft Windowsboth on KEV

Affected Assets

adobe
coldfusion
10.0, 9.0, 9.0.1, 9.0.2

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References