# CVE-2013-0632

## Summary

- **CVE ID:** CVE-2013-0632
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Jan 17, 2013
- **Last Modified:** Sep 16, 2026

## Description

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.exploit-db.com/exploits/30210)
- [CNA](http://www.adobe.com/support/security/bulletins/apsb13-03.html)
- [CNA](http://www.adobe.com/support/security/advisories/apsa13-01.html)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0632)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 92.25%
- **EPSS Percentile:** 99.7

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Mar 3, 2022
- **Due Date:** Mar 24, 2022

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._