Skip to content
COOEY

EXPOSURES › CVE-2017-1000486

CVE-2017-1000486

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-1000486 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Primetek Primefaces suffered a remote code execution flaw due to weak encryption that was actively exploited in the wild.

The Primetek Primefaces application contained a remote code execution vulnerability stemming from weak encryption, which was actively exploited in the wild. DIB organizations must ensure their third-party software components are patched and monitored for KEV-listed vulnerabilities to prevent attackers from executing arbitrary code on their systems. This failure highlights the risk of relying on unpatched or poorly secured commercial off-the-shelf (COTS) applications in a defense environment.

Shame score — The vulnerability was actively exploited in the wild and listed on CISA's KEV catalog, indicating a severe, avoidable failure to patch known weaknesses in a commercial application.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.