CISA Known Exploited Vulnerability

CVE-2020-5741

Plex · Media Server

Plex Media Server Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-502
Ransomware Unknown

CISA description

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.

Required action

Apply updates per vendor instructions.