Cyber Posture

CVE-2025-49551

High

Published: 08 July 2025

Published
08 July 2025
Modified
11 July 2025
KEV Added
Patch
CVSS Score 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0020 42.0th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-49551 is a high-severity Use of Hard-coded Credentials (CWE-798) vulnerability in Adobe Coldfusion. Its CVSS base score is 8.8 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 42.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SI-2 (Flaw Remediation) and AC-6 (Least Privilege).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploitation for Privilege Escalation (T1068) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly remediates the hard-coded credentials vulnerability by requiring timely installation of vendor patches for affected ColdFusion versions.

prevent

Prevents exploitation from adjacent network access (AV:A) by monitoring and controlling communications to the vulnerable internal IP-restricted component.

prevent

Limits the scope and impact of privilege escalation enabled by the hard-coded credentials through enforcement of least privilege access.

MITRE ATT&CK Enterprise TechniquesAI

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
T1078 Valid Accounts Stealth
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
Why these techniques?

Hard-coded credentials (CWE-798) directly enable unauthenticated privilege escalation (T1068) via valid/default accounts (T1078).

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive systems or data. Exploitation of this…

more

issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.

Deeper analysisAI

CVE-2025-49551 is a Use of Hard-coded Credentials vulnerability (CWE-798) affecting Adobe ColdFusion versions 2025.2, 2023.14, 2021.20, and earlier. This flaw enables privilege escalation, allowing unauthorized access to sensitive systems or data. The vulnerable component is restricted to internal IP addresses, and exploitation requires no user interaction. The issue has a CVSS v3.1 base score of 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its potential for significant confidentiality, integrity, and availability impacts.

An attacker with adjacent network access (AV:A) can exploit this vulnerability with low complexity (AC:L) and no prior privileges (PR:N). No user interaction is needed (UI:N), and the scope remains unchanged (S:U). Successful exploitation grants high-level access to sensitive systems or data, facilitating privilege escalation without authentication.

Adobe's security bulletin APSB25-69, available at https://helpx.adobe.com/security/products/coldfusion/apsb25-69.html, details mitigation steps and patches for affected ColdFusion versions. Security practitioners should consult this advisory for specific remediation guidance.

Details

CWE(s)

Affected Products

adobe
coldfusion
2021, 2023, 2025

CVEs Like This One

CVE-2025-61813Same product: Adobe Coldfusion
CVE-2025-61811Same product: Adobe Coldfusion
CVE-2025-54261Same product: Adobe Coldfusion
CVE-2026-34619Same product: Adobe Coldfusion
CVE-2026-27306Same product: Adobe Coldfusion
CVE-2025-61808Same product: Adobe Coldfusion
CVE-2025-49535Same product: Adobe Coldfusion
CVE-2026-27282Same product: Adobe Coldfusion
CVE-2025-61809Same product: Adobe Coldfusion
CVE-2025-61821Same product: Adobe Coldfusion

References