CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-45354

High Severity
SVRS
45/100

CVSSv3
4.3/10

EPSS
0.00019/1

CVE-2024-45354 is a code execution vulnerability found in the Xiaomi shop application. Attackers can exploit this vulnerability via improper input validation to potentially execute malicious code. While the CVSS score is 4.3, indicating moderate severity, the SOCRadar Vulnerability Risk Score (SVRS) is 45. This SVRS score suggests the vulnerability is not considered critical according to SOCRadar's intelligence. However, businesses should still consider the possibility of exploit amplification, as the SVRS considers threat actor activity and exploit availability. Successful exploitation can lead to unauthorized access and system compromise on devices running the vulnerable Xiaomi shop application. It is crucial to apply the necessary patches or mitigation measures to prevent potential attacks. Even with a moderate rating, the risk of potential data breaches and reputational damage remains, highlighting the importance of proactive security measures. This issue should be included in your organization's vulnerability management program.

No tags available
CVSS:3.1
AV:N
AC:L
PR:N
UI:R
S:U
C:L
I:N
A:N
2025-03-27

2025-03-27

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-45354 | Xiaomi Shop Application origin validation
vuldb.com2025-03-27
CVE-2024-45354 | Xiaomi Shop Application origin validation | A vulnerability was found in Xiaomi Shop Application. It has been classified as problematic. This affects an unknown part. The manipulation leads to origin validation error. This vulnerability is uniquely identified as CVE-2024-45354. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
rss
forum
news

Social Media

CVE-2024-45354 A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attacker… https://t.co/geDmV1epqw
0
1
2

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=552

CWE Details

CWE IDCWE NameDescription
CWE-346Origin Validation ErrorThe software does not properly verify that the source of data or communication is valid.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence