A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to leak sensitive user information.
History

Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 07:30:00 +0000

Type Values Removed Values Added
Description A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to leak sensitive user information.
Title Mi Connect Service APP protocol flaws lead to leaking sensitive user information
Weaknesses CWE-319
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Xiaomi

Published: 2025-03-27T07:16:21.898Z

Updated: 2025-03-27T13:31:06.739Z

Reserved: 2024-08-28T02:24:48.946Z

Link: CVE-2024-45361

cve-icon Vulnrichment

Updated: 2025-03-27T13:31:02.253Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-27T08:15:17.263

Modified: 2025-03-27T16:45:27.850

Link: CVE-2024-45361

cve-icon Redhat

No data.