EXPOSURES › CVE-2017-1000486
CVE-2017-1000486
HIGH ⌖ ON CISA KEV · EXPLOITEDPrimetek Primefaces suffered a remote code execution flaw due to weak encryption that was actively exploited in the wild.
The Primetek Primefaces application contained a remote code execution vulnerability stemming from weak encryption, which was actively exploited in the wild. DIB organizations must ensure their third-party software components are patched and monitored for KEV-listed vulnerabilities to prevent attackers from executing arbitrary code on their systems. This failure highlights the risk of relying on unpatched or poorly secured commercial off-the-shelf (COTS) applications in a defense environment.
Shame score — The vulnerability was actively exploited in the wild and listed on CISA's KEV catalog, indicating a severe, avoidable failure to patch known weaknesses in a commercial application.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution