A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to leak sensitive user information.
History

Thu, 27 Mar 2025 07:30:00 +0000

Type Values Removed Values Added
Description A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to leak sensitive user information.
Title Mi Connect Service APP protocol flaws lead to leaking sensitive user information
Weaknesses CWE-319
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Xiaomi

Published: 2025-03-27T07:16:21.898Z

Updated: 2025-03-27T07:22:18.725Z

Reserved: 2024-08-28T02:24:48.946Z

Link: CVE-2024-45361

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-03-27T08:15:17.263

Modified: 2025-03-27T08:15:17.263

Link: CVE-2024-45361

cve-icon Redhat

No data.