XiaomiGetApps Code Execution Vulnerability
CVE-2023-26324
9.8CRITICAL
Key Information:
- Vendor
- Xiaomi
- Status
- Getapps Application
- Vendor
- CVE Published:
- 28 August 2024
Summary
A vulnerability in the XiaomiGetApps application exists due to a flaw in the verification logic. This oversight permits an attacker to bypass built-in security measures, enabling them to execute arbitrary code on affected devices. As a result, the integrity and security of the application can be severely compromised, leading to potential unauthorized access and exploitation by malicious actors.
Affected Version(s)
GetApps application GetApps application <= 30.6.0.2
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database