CVE-2017-5947
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/03/2018
Last modified:
12/08/2021
Description
An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in turn could allow for downgrading partitions such as the Android Bootloader.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:oneplus:oxygenos:*:*:*:*:*:*:*:* | 5.0 (including) | |
| cpe:2.3:h:oneplus:oneplus_2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:oneplus:oneplus_3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:oneplus:oneplus_3t:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:oneplus:oneplus_5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:oneplus:oneplus_one:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:oneplus:oneplus_x:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



