SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-43566

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read.

MEDIUM 6.8EPSS 55.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 55.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
EPSS
55.11% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
adobe/coldfusion
Source
psirt@adobe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.