CVE-2023-26324: GetApps application has code execution vulnerability
Published Aug 28, 2024
·Updated
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.
Affected Software
1 affected component
Mi GetApps<30.6.0.2
Event History
Aug 28, 2024
CVE Published
via MITRE·07:28 AM
Data Sourced
via MITRE·07:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-26324?
CVE-2023-26324 is a high-severity code execution vulnerability in the XiaomiGetApps application.
2
How do I fix CVE-2023-26324?
To fix CVE-2023-26324, update the XiaomiGetApps application to version 30.6.0.2 or higher.
3
What causes the CVE-2023-26324 vulnerability?
The vulnerability CVE-2023-26324 is caused by a bypass in the verification logic of the XiaomiGetApps application.
4
Who is affected by CVE-2023-26324?
Users of the XiaomiGetApps application versions below 30.6.0.2 are affected by CVE-2023-26324.
5
What can an attacker do with CVE-2023-26324?
An attacker can exploit CVE-2023-26324 to execute malicious code on the affected devices.