CVE-2024-20767
HIGH
7,4
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none
Description
AI Translation Available
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,9415
Percentile
1,0th
Updated
EPSS Score Trend (Last 90 Days)
284
Improper Access Control
IncompleteCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Varies By Context
Applicable Platforms
Technologies:
ICS/OT, Not Technology-Specific, Web Based
Exploit
Adobe ColdFusion 2023.6 - Remote File Read
Adobe ColdFusion 2023.6 - Remote File Read
View Exploit Code →
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update11:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update12:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update6:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update8:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update5:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update9:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update10:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Coldfusion by Adobe
CPE Identifier
View Detailed Analysis
cpe:2.3:a:adobe:coldfusion:2021:update7:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024…
https://helpx.adobe.com/security/products/coldfusion/apsb24-14.html
https://helpx.adobe.com/security/products/coldfusion/apsb24-14.html