PT-2017-3176 · Oneplus · Oxygenos

Roee Hay

·

Published

2017-03-01

·

Updated

2019-10-03

·

CVE-2017-5626

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OxygenOS versions prior to 4.0.2
Description The issue is related to insufficient access control in OxygenOS, allowing an attacker to exploit hidden fastboot oem commands (4F500301 and 4F500302) to lock or unlock the bootloader without user confirmation or a factory reset. This enables persistent code execution with high privileges, providing complete access to user data. The exploitation can lead to an attacker gaining root privileges and disclosing protected information by replacing the system partition with a malicious one.
Recommendations For OxygenOS versions prior to 4.0.2, update to version 4.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the fastboot oem commands (4F500301 and 4F500302) to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02592
CVE-2017-5626

Affected Products

Oxygenos