PT-2017-18581 · Oneplus · Oneplus One+1

Roee Hay

·

Published

2017-05-11

·

Updated

2019-10-03

·

CVE-2017-8851

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions OnePlus One versions (affected versions not specified) OnePlus X versions (affected versions not specified)
Description An issue allows attackers to install OTAs of one product over the other, even on locked bootloaders, due to a lenient updater-script and shared OTA verification keys. This could lead to the exploitation of patched vulnerabilities and expansion of the attack surface. The device may become unusable until a Factory Reset is performed. The vulnerability can be exploited by Man-in-the-Middle (MiTM) attackers targeting the update process, as it does not occur over TLS. Physical attackers can also reboot the phone into recovery and use 'adb sideload' to push the OTA.
Recommendations For OnePlus One, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For OnePlus X, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8851

Affected Products

Oneplus One
Oneplus X