CVE-2017-1000486 is a critical remote code execution vulnerability affecting Primetek Primefaces 5.x, stemming from a weak encryption flaw (CWE-326). With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code remotely over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited, as confirmed by its presence in the KEV catalog and high EPSS score, indicating a significant likelihood of exploitation. Publicly available exploit modules, including Metasploit and Nuclei templates, along with extensive community discussion and media coverage, underscore its widespread recognition and active threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0, <= 4.0.24CPE matchmatch criteria | cpe:2.3:a:primetek:primefaces:*:*:*:*:*:*:*:* | ||
>= 5.0, < 5.2.21CPE matchmatch criteria | cpe:2.3:a:primetek:primefaces:*:*:*:*:*:*:*:* | ||
>= 5.3, < 5.3.8CPE matchmatch criteria | cpe:2.3:a:primetek:primefaces:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.