« Volver al listado

CVE-2017-5947

Estado: ModificadaMedia (6.8)—

An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in turn could allow for downgrading partitions such as the Android Bootloader.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-5947",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-03-29T18:29:01.310",
  "references": [
    {
      "url": "https://alephsecurity.com/vulns/aleph-2017007",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://alephsecurity.com/vulns/aleph-2017007",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in turn could allow for downgrading partitions such as the Android Bootloader."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema en dispositivos OnePlus One, X, 2, 3, 3T y 5 con OxygenOS 5.0 y anteriores. El atacante puede reiniciar el dispositivo en modo Qualcomm Emergency Download (EDL) mediante ADB o empleando la tecla de subir volumen al estar conectado a USB. Esto podría permitir la degradación de particiones como Android Bootloader."
    }
  ],
  "lastModified": "2026-06-17T01:21:29.493",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:oneplus:oxygenos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A8EE237-7537-4691-9B54-2287B47C1695",
              "versionEndIncluding": "5.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:oneplus:oneplus_2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "332B048C-6522-41A7-9DAB-834FBFCA3C00"
            },
            {
              "criteria": "cpe:2.3:h:oneplus:oneplus_3:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E6B1891E-38B0-42C5-89D3-3DC12217F087"
            },
            {
              "criteria": "cpe:2.3:h:oneplus:oneplus_3t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4C7E02CB-9EAC-4BFD-8CCC-337610E1CCEE"
            },
            {
              "criteria": "cpe:2.3:h:oneplus:oneplus_5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F179266A-2A67-4A9D-89E6-B3CCE4430A68"
            },
            {
              "criteria": "cpe:2.3:h:oneplus:oneplus_one:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8B8AD37A-7539-4F16-8AC2-2556035B0DE2"
            },
            {
              "criteria": "cpe:2.3:h:oneplus:oneplus_x:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C0A390FA-9B56-4645-991D-5E9CB16966B9"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}