CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-45346: GetApps application has code execution vulnerability

8.8 CVSS

Description

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

Classification

CVE ID: CVE-2024-45346

CVSS Base Severity: HIGH

CVSS Base Score: 8.8

Affected Products

Vendor: Xiaomi

Product: GetApps application

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-07 (when was this score calculated)

References

https://trust.mi.com/misrc/bulletins/advisory?cveId=545

Timeline