CVE-2020-14121: Medium severity mi mi app store vulnerability
Published Apr 21, 2022
·Updated
A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, and an attacker can exploit the vulnerability to perform a local silent installation.
Affected Software
1 affected component
Mi Mi App Store=4.12.2
Event History
Apr 21, 2022
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this business logic vulnerability?
The vulnerability ID is CVE-2020-14121.
2
What is the description of CVE-2020-14121?
CVE-2020-14121 is a business logic vulnerability in Mi App Store that allows for local silent installation by bypassing permission checks.
3
What is the severity of CVE-2020-14121?
The severity of CVE-2020-14121 is medium with a severity value of 5.5.
4
Which software version is affected by CVE-2020-14121?
Version 4.12.2 of Mi App Store is affected by CVE-2020-14121.
5
Where can I find more information about CVE-2020-14121?
You can find more information about CVE-2020-14121 at the following link: https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=146