Primefaces Remote Code Execution Exploit
Title source: metasploitDescription
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
Exploits (10)
exploitdb
WORKING POC
by Bjoern Schuette · rubywebappsjava
https://www.exploit-db.com/exploits/43733
metasploit
WORKING POC
EXCELLENT
by Bjoern Schuette, h00die · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/primefaces_weak_encryption_rce.rb
Nuclei Templates (1)
Primetek Primefaces 5.x - Remote Code Execution
CRITICALby Moritz Nentwig
References (5)
Scores
CVSS v3
9.8
EPSS
0.9364
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Lab Environment
COMMUNITY
Community Lab
+6 more repos
Details
CISA KEV
2022-01-10
VulnCheck KEV
2021-01-05
InTheWild.io
2022-01-10
ENISA EUVD
EUVD-2021-1339
CWE
CWE-326
Status
published
Products (2)
org.primefaces/primefaces
5.0 - 6.0Maven
primetek/primefaces
4.0 - 4.0.24
Published
Jan 03, 2018
KEV Added
Jan 10, 2022
Tracked Since
Feb 18, 2026