Lucene search

K
cveMitreCVE-2017-5554
HistoryJan 23, 2017 - 7:59 a.m.

CVE-2017-5554

2017-01-2307:59:00
CWE-287
mitre
web.nvd.nist.gov
29
aboot
oneplus 3
oneplus 3t
oxygenos
cve-2017-5554
fastboot mode
authentication bypass
selinux
permissive mode

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.004

Percentile

74.7%

An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authentication. A physical attacker can press the “Volume Up” button during device boot, where an attacker with ADB access can issue the adb reboot bootloader command. Then, the attacker can put the platform’s SELinux in permissive mode, which severely weakens it, by issuing: fastboot oem selinux permissive.

Affected configurations

Nvd
Node
oneplusoxygenosRange3.2.8
AND
oneplusoneplus_3Match-
Node
oneplusoxygenosRange3.5.4
AND
oneplusoneplus_3tMatch-
VendorProductVersionCPE
oneplusoxygenos*cpe:2.3:o:oneplus:oxygenos:*:*:*:*:*:*:*:*
oneplusoneplus_3-cpe:2.3:h:oneplus:oneplus_3:-:*:*:*:*:*:*:*
oneplusoneplus_3t-cpe:2.3:h:oneplus:oneplus_3t:-:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.004

Percentile

74.7%

Related for CVE-2017-5554