Impact
ColdFusion suffers from an Improper Input Validation weakness that can be abused by an attacker with high privileges to crash the application, resulting in a denial-of-service condition. The vulnerability does not require any user interaction, and the impact is limited to disrupting the availability of the affected application.
Affected Systems
The flaw affects Adobe ColdFusion 2023 and Adobe ColdFusion 2025.
Risk and Exploitability
The CVSS score of 4.9 indicates a medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires an attacker to possess high privileges on the system or application, and the CVE description notes that user interaction is not required, but it does not explicitly state whether or not a network connection is needed. This lack of clarity means the presence of a network exploitation requirement remains an unverified assumption.
OpenCVE Enrichment