CVE-2017-8850
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both ROMs use the same OTA verification keys, attackers can install HydrogenOS over OxygenOS and vice versa, even on locked bootloaders, which allows for exploitation of vulnerabilities patched on one image but not on the other, in addition to expansion of the attack surface. This vulnerability can be exploited by Man-in-the-Middle (MiTM) attackers targeting the update process. This is possible because the update transaction does not occur over TLS (CVE-2016-10370). In addition, physical attackers can reboot the phone into recovery, and then use 'adb sideload' to push the OTA (on OnePlus 3/3T 'Secure Start-up' must be off).
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.43%
- Percentil entre todas las CVEs puntuadas: 35
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-319
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-8850",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-05-11T18:29:00.250",
"references": [
{
"url": "https://alephsecurity.com/vulns/aleph-2017020",
"tags": [
"Exploit",
"Issue Tracking",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://alephsecurity.com/vulns/aleph-2017020",
"tags": [
"Exploit",
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both ROMs use the same OTA verification keys, attackers can install HydrogenOS over OxygenOS and vice versa, even on locked bootloaders, which allows for exploitation of vulnerabilities patched on one image but not on the other, in addition to expansion of the attack surface. This vulnerability can be exploited by Man-in-the-Middle (MiTM) attackers targeting the update process. This is possible because the update transaction does not occur over TLS (CVE-2016-10370). In addition, physical attackers can reboot the phone into recovery, and then use 'adb sideload' to push the OTA (on OnePlus 3/3T 'Secure Start-up' must be off)."
},
{
"lang": "es",
"value": "Se descubrió un problema en los dispositivos OnePlus One, X, 2, 3 y 3T. Debido a un script de actualización en las imágenes OTA de OnePlus, y el hecho de que ambas ROM utilicen las mismas claves de verificación OTA. Los atacantes pueden instalar HydrogenOS sobre OxygenOS y viceversa, incluso en cargadores de arranque bloqueados, lo que permite la explotación de vulnerabilidades parcheadas en una imagen pero no en la otra, además de la expansión de la superficie de ataque. Esta vulnerabilidad puede ser explotada por atacantes Man-in-the-Middle (MiTM) que apuntan al proceso de actualización. Esto es posible porque la transacción de actualización no se produce sobre TLS (CVE-2016-10370). Además, los atacantes físicos pueden reiniciar el teléfono en la recuperación y, a continuación, utilizar 'sbdb sideload' en la OTA (en OnePlus 3/3T 'Secure Start-up' debe estar apagado)."
}
],
"lastModified": "2026-06-17T01:27:04.690",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:oneplus:oxygenos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8189780A-EA20-4B96-A625-48D12948B3F2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:oneplus:oneplus_2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "332B048C-6522-41A7-9DAB-834FBFCA3C00"
},
{
"criteria": "cpe:2.3:h:oneplus:oneplus_3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E6B1891E-38B0-42C5-89D3-3DC12217F087"
},
{
"criteria": "cpe:2.3:h:oneplus:oneplus_3t:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4C7E02CB-9EAC-4BFD-8CCC-337610E1CCEE"
},
{
"criteria": "cpe:2.3:h:oneplus:oneplus_one:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8B8AD37A-7539-4F16-8AC2-2556035B0DE2"
},
{
"criteria": "cpe:2.3:h:oneplus:oneplus_x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C0A390FA-9B56-4645-991D-5E9CB16966B9"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}