CVE-2017-5554 Information
Description
An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode which could be done without any authentication. A physical attacker can press the \Volume Up\ button during device boot where an attacker with ADB access can issue the adb reboot bootloader command. Then the attacker can put the platform’s SELinux in permissive mode which severely weakens it by issuing: fastboot oem selinux permissive.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/95706 https://securityresear.ch/2017/01/11/fastboot-oem-selinux-permissive/ https://www.xda-developers.com/oneplus-33t-bootloader-vulnerability-allows-changing-of-selinux-to-permissive-mode-in-fastboot/
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: