CVE-2017-1000486

CRITICAL KEV NUCLEI LAB

Primefaces Remote Code Execution Exploit

Title source: metasploit

Description

Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

Exploits (10)

exploitdb WORKING POC
by Bjoern Schuette · rubywebappsjava
https://www.exploit-db.com/exploits/43733
nomisec WORKING POC 92 stars
by pimps · remote
https://github.com/pimps/CVE-2017-1000486
nomisec WORKING POC 18 stars
by 0xdsm · poc
https://github.com/0xdsm/pwnfaces
nomisec WORKING POC 9 stars
by mogwailabs · remote
https://github.com/mogwailabs/CVE-2017-1000486
nomisec WORKING POC 3 stars
by Pastea · remote
https://github.com/Pastea/CVE-2017-1000486
nomisec WRITEUP
by jam620 · remote
https://github.com/jam620/primefaces
nomisec WORKING POC
by LongWayHomie · remote
https://github.com/LongWayHomie/CVE-2017-1000486
nomisec STUB
by cved-sources · poc
https://github.com/cved-sources/cve-2017-1000486
vulncheck_xdb WORKING POC
remote
https://github.com/000pp/pwnfaces
metasploit WORKING POC EXCELLENT
by Bjoern Schuette, h00die · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/primefaces_weak_encryption_rce.rb

Nuclei Templates (1)

Primetek Primefaces 5.x - Remote Code Execution
CRITICALby Moritz Nentwig

Scores

CVSS v3 9.8
EPSS 0.9364
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-01-10
VulnCheck KEV 2021-01-05
InTheWild.io 2022-01-10
ENISA EUVD EUVD-2021-1339
CWE
CWE-326
Status published
Products (2)
org.primefaces/primefaces 5.0 - 6.0Maven
primetek/primefaces 4.0 - 4.0.24
Published Jan 03, 2018
KEV Added Jan 10, 2022
Tracked Since Feb 18, 2026