A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.
History

Thu, 29 Aug 2024 02:45:00 +0000

Type Values Removed Values Added
Description The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life. A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

Wed, 28 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Xiaomi
Xiaomi getapps Application
Weaknesses CWE-94
CPEs cpe:2.3:a:xiaomi:getapps_application:*:*:*:*:*:*:*:*
Vendors & Products Xiaomi
Xiaomi getapps Application
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 28 Aug 2024 11:30:00 +0000

Type Values Removed Values Added
Description A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code. The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life.

Wed, 28 Aug 2024 07:45:00 +0000

Type Values Removed Values Added
Description The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life. A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

Wed, 28 Aug 2024 07:00:00 +0000

Type Values Removed Values Added
Description The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life.
Title GetApps application has code execution vulnerability
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Xiaomi

Published: 2024-08-28T06:44:40.297Z

Updated: 2024-08-29T02:24:43.318Z

Reserved: 2024-08-28T02:24:34.837Z

Link: CVE-2024-45346

cve-icon Vulnrichment

Updated: 2024-08-28T13:44:57.859Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-28T07:15:08.823

Modified: 2024-08-29T03:15:05.247

Link: CVE-2024-45346

cve-icon Redhat

No data.