Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jj3-7hg7-2w24

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm/normal} command' in contradiction to the threat model of Android where the bootloader MUST NOT allow any security-sensitive operation to be run unless the bootloader is unlocked.

An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm/normal} command' in contradiction to the threat model of Android where the bootloader MUST NOT allow any security-sensitive operation to be run unless the bootloader is unlocked.

EPSS

Процентиль: 15%
0.00049
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.6
nvd
почти 9 лет назад

An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm/normal} command' in contradiction to the threat model of Android where the bootloader MUST NOT allow any security-sensitive operation to be run unless the bootloader is unlocked.

EPSS

Процентиль: 15%
0.00049
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-269