SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-14116

An intent redirection vulnerability in the Mi Browser product.

HIGH 7.5EPSS 0.44%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the incoming data. Attackers can perform sensitive operations by exploiting this.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
0.44% probability · 37th percentile
CISA KEV
Not listed
Weakness
CWE-345
Affected
mi/mi browser
Source
security@xiaomi.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.