Impact
The vulnerability involves a hard‑coded cryptographic key, identified as CWE‑321. An attacker with low privileges can exploit this flaw to bypass security controls, gaining unauthorized read and write capabilities. The flaw can be triggered without user interaction, and the scope of impact is broadened due to changes in affected components.
Affected Systems
Adobe offers ColdFusion 2023 and ColdFusion 2025 as the affected products. All releases of these versions that contain the hard‑coded key are susceptible; the issue is mitigated only in the latest patched releases.
Risk and Exploitability
The CVSS score of 8.4 signifies a high severity level, while an EPSS score of less than 1% indicates a low probability of being actively exploited, and the vulnerability is not listed in the KEV catalog. The attack can be carried out from a low‑privileged context within the application environment, without requiring user interaction; once executed, the attacker can read and modify protected data, posing a significant threat to confidentiality, integrity, and availability.
OpenCVE Enrichment