CVE-2024-45361

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 27, 2025
CWE ID 319

Summary

CVE-2024-45361 is a newly identified protocol flaw vulnerability affecting the Xiaomi Mi Connect Service APP. The issue arises due to a faulty validation logic within the app, enabling attackers to steal sensitive user information without proper authorization. This weakness could potentially put users' privacy at risk and necessitates immediate attention from Xiaomi to release a patch to mitigate this vulnerability. Users are advised to exercise caution when using the app and ensure their devices' software is up-to-date to protect against potential exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share