Skip to content
COOEY

EXPOSURES › CVE-2020-5741

CVE-2020-5741

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-03-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-5741 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Plex Media Server RCE due to malicious uploads

Plex's Media Server allowed attackers to upload malicious files through the Camera Upload feature, enabling remote code execution. This was actively exploited in the wild, posing a significant security risk to DIB organizations using the product.

Shame score — Active exploitation of a remote code execution vulnerability by an unauthorized party.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.