PT-2018-8289 · Google+2 · Android Bootloader+2
Roee Hay
+1
·
Publicado
2018-03-29
·
Atualizado
2021-08-12
·
CVE-2017-5947
CVSS v3.1
6.8
Média
| Vetor | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OnePlus devices versions OxygenOS 5.0 and earlier
Description
An issue allows an attacker to reboot the device into the Qualcomm Emergency Download (EDL) mode, potentially enabling the downgrading of partitions such as the Android Bootloader. This can be achieved through ADB or by using the Volume-Up button when connected to USB.
Recommendations
For OxygenOS 5.0 and earlier, consider restricting access to ADB and physical interactions with the device, such as limiting the use of the Volume-Up button when connected to USB, until a patch is available. As a temporary workaround, restrict physical access to the device to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Android Bootloader
Oxygenos
Qualcomm Emergency Download (Edl) Mode