TROYANOSYVIRUS
Back to CVEs

CVE-2020-5741

HIGHCISA KEV
7.2

Description

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

CVE Details

CVSS v3.1 Score7.2
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published5/8/2020
Last Modified10/31/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorPlex
ProductMedia Server
Vulnerability NamePlex Media Server Remote Code Execution Vulnerability
KEV Date Added2023-03-10
Remediation Due Date2023-03-31
Ransomware UseUnknown

Affected Products

microsoft:windowsplex:media_server

Weaknesses (CWE)

CWE-502CWE-502

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.