Code Execution Vulnerability in XiaomiGetApps App
CVE-2023-26322

9.8CRITICAL

Key Information:

Vendor
Xiaomi
Status
Getapps Application
Vendor
CVE Published:
28 August 2024

Summary

A significant code execution vulnerability in the XiaomiGetApps application can be exploited by attackers due to a flaw in the verification logic. This critical security issue permits unauthorized execution of malicious code, potentially compromising user devices and data security. Users of the affected application are urged to apply the necessary patches to safeguard against this threat.

Affected Version(s)

GetApps application GetApps application <= 31.2.5.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.