S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-1000486 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Primetek Primefaces affects v. 5.x.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2017-1000486
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Primetek Primefaces 5.x is a popular JavaServer Faces (JSF) component suite that is used by developers worldwide to build user interfaces for web applications. This suite includes over 100 customizable UI widgets, charts, AJAX functionality and other useful tools. Primetek Primefaces simplifies the web development process and provides a more streamlined user experience.

Unfortunately, this powerful technology is not entirely safe. A massive security lapse has been detected in Primetek Primefaces 5.x, known as CVE-2017-1000486. This vulnerability allows remote code execution, creating a significant security threat for many web applications that use Primetek Primefaces. It has been on the National Vulnerability Database since May 2017.

When exploited, the vulnerability could allow attackers to perform unauthorized actions on a web application, leading to data theft, manipulation, or even total control of the system. An attacker can use the vulnerability to execute arbitrary code remotely, leaving the targeted web application and its users susceptible to various attacks, including data exfiltration, privilege escalation, or even destruction of the web application.

At s4e.io, our pro security features make it possible for individuals and organizations to get access to the latest information concerning vulnerabilities that affect their digital assets. Our service provides vulnerability monitoring and assessment tools that cater to newly detected vulnerabilities. You can easily subscribe to our services and get the latest updates on this and other security weaknesses that may impact your IT security. In conclusion, Primetek Primefaces 5.x is a quintessential component suite that has played a vital role in simplifying web application development, but its vulnerability makes it an unfavorable candidate for web development. Therefore, individuals and organizations that use the suite must take necessary precautions to protect their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of Primetek Primefaces 5.x should take the following precautions:

  • Update to the latest version of Primefaces.
  • Conduct regular security reviews and vulnerability scans of all code and applications.
  • Create strong passwords and never use the same password for multiple logins.
  • Implement multi-factor authentication wherever possible.
  • Follow best practices for secure coding, including input validation and using encryption where necessary.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-1000486 scanner - Remote Code Execution (RCE) vulnerability in Primetek Primefaces | S4E