Vulnerability Details CVE-2017-5947
An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in turn could allow for downgrading partitions such as the Android Bootloader.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.8%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 4.6
Products affected by CVE-2017-5947
-
cpe:2.3:h:oneplus:oneplus_2:-
-
cpe:2.3:h:oneplus:oneplus_3:-
-
cpe:2.3:h:oneplus:oneplus_3t:-
-
cpe:2.3:h:oneplus:oneplus_5:-
-
cpe:2.3:h:oneplus:oneplus_one:-
-
cpe:2.3:h:oneplus:oneplus_x:-
-
cpe:2.3:o:oneplus:oxygenos:3.2.8
-
cpe:2.3:o:oneplus:oxygenos:3.5.4
-
cpe:2.3:o:oneplus:oxygenos:4.0.2
-
cpe:2.3:o:oneplus:oxygenos:4.0.3
-
cpe:2.3:o:oneplus:oxygenos:5.0