CVE-2023-26323

HIGH

Xiaomi App Market - RCE

Title source: llm
STIX 2.1

Description

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.

Scores

CVSS v3 7.6
EPSS 0.0019
EPSS Percentile 40.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-95
Status published
Products (1)
mi/app_market 4.57.4 - 4.58.2
Published Aug 28, 2024
Tracked Since Feb 18, 2026