PT-2017-18581 · Oneplus · Oneplus One+1
Roee Hay
·
Published
2017-05-11
·
Updated
2019-10-03
·
CVE-2017-8851
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OnePlus One versions (affected versions not specified)
OnePlus X versions (affected versions not specified)
Description
An issue allows attackers to install OTAs of one product over the other, even on locked bootloaders, due to a lenient updater-script and shared OTA verification keys. This could lead to the exploitation of patched vulnerabilities and expansion of the attack surface. The device may become unusable until a Factory Reset is performed. The vulnerability can be exploited by Man-in-the-Middle (MiTM) attackers targeting the update process, as it does not occur over TLS. Physical attackers can also reboot the phone into recovery and use 'adb sideload' to push the OTA.
Recommendations
For OnePlus One, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For OnePlus X, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oneplus One
Oneplus X