Protocol Flaw in Xiaomi Mi Connect Service App Exposes User Data
CVE-2024-45361

6.5MEDIUM

Key Information:

Vendor
Xiaomi
Vendor
CVE Published:
27 March 2025

Summary

A protocol flaw exists in the Xiaomi Mi Connect Service App, allowing attackers to exploit inadequate validation logic. This vulnerability can lead to unauthorized access and potential leakage of sensitive user information, compromising user data security.

Affected Version(s)

Xiaomi Mi Connect Service Xiaomi Mi Connect Service 3.1.895.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.