CVE-2017-1000486

Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

Basic Information

CVE State
PUBLISHED
Reserved Date
January 03, 2018
Published Date
January 03, 2018
Last Updated
February 07, 2025
Vendor
n/a
Product
n/a
Description
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

CVSS Scores

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2022-01-10 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2023-12-15 00:04:21 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-01-10 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

primefaces_weak_encryption_rce

Type: metasploit • Created: Unknown

Metasploit module for CVE-2017-1000486

LongWayHomie/CVE-2017-1000486

Type: github • Created: 2023-12-15 00:04:21 UTC • Stars: 0

Remote Code Execution exploit for PrimeFaces 5.x - EL Injection (CVE-2017-1000486)

Pastea/CVE-2017-1000486

Type: github • Created: 2021-08-05 17:42:54 UTC • Stars: 3

mogwailabs/CVE-2017-1000486

Type: github • Created: 2018-10-17 22:47:30 UTC • Stars: 9

Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)

pimps/CVE-2017-1000486

Type: github • Created: 2018-09-03 03:11:24 UTC • Stars: 90

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit