Remote Code Execution Vulnerability in Plex Media Server by Plex
CVE-2019-19141

8.8HIGH

Key Information:

Vendor

Plex

Vendor
CVE Published:
19 December 2019

What is CVE-2019-19141?

The Camera Upload feature in Plex Media Server version 1.18.2.2029 is prone to a vulnerability that allows remote authenticated users to write files in unauthorized locations. By exploiting this flaw, attackers can perform directory traversal, potentially creating a .ssh directory in the home folder of the Plex user on systems like Ubuntu. This manipulation can lead to uploading an SSH authorized_keys file, granting attackers unauthorized access to the server via SSH, thereby compromising system integrity and security.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.