Signature
alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"POLICY-OTHER Adobe ColdFusion admin interface access attempt"; flow:to_server,established; content:"/CFIDE/administrator"; fast_pattern:only; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy max-detect-ips drop, policy security-ips drop, service http; reference:bugtraq,57330; reference:cve,2013-0632; reference:url,www.adobe.com/support/security/advisories/apsa13-01.html; classtype:policy-violation; sid:25975; rev:3;)
Recommendations/Investigative actions
It is recommended to investigate the source of the traffic to determine whether it's a legitimate access attempt or a potential threat. It is recommended to deny access from an external network to the Adobe ColdFusion administration interface, If there is a need to allow external access to the Adobe ColdFusion administration interface, enable access to specific assets.