CVE-2020-14120: High severity miui vulnerability
Published Apr 21, 2022
·Updated
Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party application to pass in parameters, and attackers can induce users to install a malicious app and use the vulnerability to achieve elevated privileges, making the normal services of the system affected.
Affected Software
1 affected component
Mi MIUI=12.5
Event History
Apr 21, 2022
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Xiaomi vulnerability?
The vulnerability ID for this Xiaomi vulnerability is CVE-2020-14120.
2
What is the severity of CVE-2020-14120?
The severity of CVE-2020-14120 is high with a CVSS score of 8.8.
3
What is the affected software for CVE-2020-14120?
The affected software for CVE-2020-14120 is Xiaomi MIUI version 12.5.
4
How can attackers exploit CVE-2020-14120?
Attackers can induce users to install a malicious app and use the vulnerability to achieve elevated privileges.
5
Is there a fix available for CVE-2020-14120?
Yes, it is recommended to update to the latest version of Xiaomi MIUI to fix CVE-2020-14120.