POLICY-OTHER Adobe ColdFusion admin interface access attempt

This alert is triggered when detecting an attempt to access the Adobe ColdFusion administration interface. Adobe ColdFusion is a powerful web application development platform. This alert may be triggered when an adversary is attempting to gain unauthorized access to the ColdFusion admin interface.

ID Number

25975

Signature

alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"POLICY-OTHER Adobe ColdFusion admin interface access attempt"; flow:to_server,established; content:"/CFIDE/administrator"; fast_pattern:only; http_uri; metadata:policy balanced-ips drop, policy connectivity-ips drop, policy max-detect-ips drop, policy security-ips drop, service http; reference:bugtraq,57330; reference:cve,2013-0632; reference:url,www.adobe.com/support/security/advisories/apsa13-01.html; classtype:policy-violation; sid:25975; rev:3;)

MITRE ATT&CK Technique

-

Severity

Low

Recommendations/Investigative actions

It is recommended to investigate the source of the traffic to determine whether it's a legitimate access attempt or a potential threat. It is recommended to deny access from an external network to the Adobe ColdFusion administration interface, If there is a need to allow external access to the Adobe ColdFusion administration interface, enable access to specific assets.