PT-2017-3176 · Oneplus · Oxygenos
Roee Hay
·
Published
2017-03-01
·
Updated
2019-10-03
·
CVE-2017-5626
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OxygenOS versions prior to 4.0.2
Description
The issue is related to insufficient access control in OxygenOS, allowing an attacker to exploit hidden fastboot oem commands (
4F500301 and 4F500302) to lock or unlock the bootloader without user confirmation or a factory reset. This enables persistent code execution with high privileges, providing complete access to user data. The exploitation can lead to an attacker gaining root privileges and disclosing protected information by replacing the system partition with a malicious one.Recommendations
For OxygenOS versions prior to 4.0.2, update to version 4.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the fastboot oem commands (
4F500301 and 4F500302) to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oxygenos