SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-14117

A improper permission configuration vulnerability in Xiaomi Content Center APP.

MEDIUM 5.3EPSS 0.69%

Does this matter?

Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.

Description

A improper permission configuration vulnerability in Xiaomi Content Center APP. This vulnerability is caused by the lack of correct permission verification in the Xiaomi content center APP, and attackers can use this vulnerability to invoke the sensitive component functions of the Xiaomi content center APP.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
0.69% probability · 51th percentile
CISA KEV
Not listed
Affected
mi/content center
Source
security@xiaomi.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.