Read Time:46 Second

What is the vulnerability?
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the ColdFusion Administrator (CFM and CFC) endpoints.

What is the Vendor Solution?

Adobe released patches for the security bypass flaws in June 2023, find more information on CVE-2023-26347 at the following reference:
[Link]

What FortiGuard Coverage is available?

FortiGuard Labs has an IPS signature “”Adobe.ColdFusion.IPFilterUtils.Authentication.Bypass” in place for CVE-2023-26347, CVE-2023-38205 since Aug 2023 and Endpoint Vulnerability signature to detect any vulnerable systems.

FortiGuard Labs recommends companies to scan their environment, find vulnerable Adobe ColdFusion servers, and upgrade as per vendor advisory and always follow best practices.

Read More