An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to Unauthorized access to the victim’s device.
History

Mon, 23 Jun 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Jun 2025 09:45:00 +0000

Type Values Removed Values Added
Description An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to Unauthorized access to the victim’s device.
Title Mi Connect Service APP protocol flaws lead to unauthorized access
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Xiaomi

Published: 2025-06-23T09:34:38.676Z

Updated: 2025-06-23T12:03:52.156Z

Reserved: 2024-08-28T02:24:34.837Z

Link: CVE-2024-45347

cve-icon Vulnrichment

Updated: 2025-06-23T12:03:00.521Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-23T10:15:26.397

Modified: 2025-06-23T20:16:21.633

Link: CVE-2024-45347

cve-icon Redhat

No data.