ID

VAR-201905-1432


TITLE

There are binary loopholes between Xiaomi Xiaoai MINI smart speaker and Xiaomi Xiaoai AI smart speaker voice device

Trust: 0.6

sources: CNVD: CNVD-2019-12775

DESCRIPTION

Xiaomi Xiaoai MINI smart speaker and Xiaomi Xiaoai AI smart speaker are both smart speaker products produced by Xiaomi Technology. There is a binary vulnerability between the Xiaomi Xiaoai MINI smart speaker and Xiaomi Xiaoai AI smart speaker voice device. Attackers can use this vulnerability to obtain the user's voice content.

Trust: 0.6

sources: CNVD: CNVD-2019-12775

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-12775

AFFECTED PRODUCTS

vendor:xiaomimodel:xiaoai ai smart speakerscope:eqversion:1.26.53

Trust: 0.6

vendor:xiaomimodel:xiaoai mini smart speaker>scope:eqversion:=1.38.5<=1.38.10

Trust: 0.6

sources: CNVD: CNVD-2019-12775

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-12775
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2019-12775
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2019-12775

PATCH

title:Binary vulnerability exists between Xiaomi smart speaker voice devicesurl:https://www.cnvd.org.cn/patchinfo/show/158041

Trust: 0.6

sources: CNVD: CNVD-2019-12775

EXTERNAL IDS

db:CNVDid:CNVD-2019-12775

Trust: 0.6

sources: CNVD: CNVD-2019-12775

SOURCES

db:CNVDid:CNVD-2019-12775

LAST UPDATE DATE

2022-05-04T09:10:17.197000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-12775date:2019-09-09T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-12775date:2019-05-18T00:00:00