← לוח פגיעויות

CVE-2020-5741

גבוהה 7.2 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Plex Media Server Remote Code Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

מדדים

CVSS 3.1
7.2 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
73% (אחוזון 100) נכון ל-30/7/2026
CWE
CWE-502

מוצרים מושפעים

plex: media server; microsoft: windows

קישורים