7.5
CVSSv3

CVE-2021-33959

Published: 18/01/2023 Updated: 08/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

plex media server

Github Repositories

CVE-2021-33959

CVE-2021-33959 It can be seen that Plex service listens to the four udp ports 32410, 32412, 32413 and 32414 Through the analysis of the attack payload and using the message format of the device query request for reference, we write software to send udp packets with the attack payload of M-SEARCH * HTTP/11 to these ports, and capture packets for the reflection source IP Final