The vulnerability was used to compromise website of the Washington state Administrative Office of the Courts (AOC).
Vulnerable component: ColdFusion
CVSSv3 score: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
CWE-ID: CWE-592 - Authentication Bypass Issues
The vulnerability allows a remote attacker to bypass authentication and gain unauthorized access to vulnerable system.
The vulnerability exists due to an error within administrator.cfc. A remote unauthenticated attacker can access Adobe ColdFusion application using a default empty password, login to the RDS component and leverage this session to access administrative web interface.
Successful exploitation of this vulnerability results in unauthorized access to Adobe ColdFusion.Note: the vulnerability was being actively exploited.
Known APT campaigns:
Washington state Administrative Office of the Courts (AOC) breach
The attack happened between September, 2012 and February, 2013. The hackers stole 160,000 SSNs, 1M driver's license numbers.
- Adobe ColdFusion APSB13-03 - Remote Exploit (Metasploit) [Exploit-DB]
- Adobe ColdFusion 9 - Administrative Login Bypass [Exploit-DB]