Vulnerability Details CVE-2017-11105
The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that partition to disable signature validation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2017-11105
-
cpe:2.3:h:oneplus:oneplus_2:-
-
cpe:2.3:o:oneplus:primary_bootloader:-