Miui
Vendor:
First CVE: Mar 6, 2020 · Active for 6 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Miui over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2020
6 years ago
Most Recent CVE
Jul 14, 2022
1,471 days ago
CVE Severity & Scoring
Miui9 CVEs
44%
56%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local4 (44.4%)
Network4 (44.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (11.1%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None7 (77.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14125HIGH A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited by attackers to make denial of | Jun 8, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-9531HIGH An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. In the Web resources of GetApps(com.xiaomi.mipicks), the parameters passed in are read and executed. After reading | Mar 6, 2020 | 7.3 | 23 | NO | NO |
CVE-2020-14120HIGH Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party application to pass in parameters, an | Apr 21, 2022 | 8.8 | 22 | NO | NO |
CVE-2020-14127HIGH A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attackers to make remote denial of se | Jul 14, 2022 | 7.5 | 19 | NO | NO |
CVE-2020-14123HIGH There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the p | Apr 22, 2022 | 7.5 | 19 | NO | NO |
CVE-2020-14103MEDIUM The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15. | Apr 8, 2021 | 5.5 | 19 | NO | NO |
CVE-2020-14105MEDIUM The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15. | Apr 20, 2021 | 5.5 | 16 | NO | NO |
CVE-2020-14106MEDIUM The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.26. | Apr 8, 2021 | 5.5 | 16 | NO | NO |
CVE-2020-14122MEDIUM Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter verification, resulting in user | Apr 21, 2022 | 5.5 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Miui
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 12.5.2 | 2 | 6.5 | 0.5% | 0 | 0 |
| 12.5 | 1 | 8.8 | 0.4% | 0 | 0 |