Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pwjc-cjmg-4g8f

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information.

With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information.

EPSS

Процентиль: 20%
0.00063
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 5.9
nvd
почти 9 лет назад

With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information.

EPSS

Процентиль: 20%
0.00063
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-276