Downgrade Vulnerability in OnePlus Devices Running OxygenOS and HydrogenOS
CVE-2017-5948

5.9MEDIUM

Key Information:

Vendor

Oneplus

Status
Vendor
CVE Published:
11 May 2017

What is CVE-2017-5948?

An issue has been identified affecting OnePlus devices including the One, X, 2, 3, and 3T that allows unauthorized downgrade attacks on the installed Operating Systems, OxygenOS and HydrogenOS. The vulnerability originates from a permissive 'updater-script' in Over-The-Air (OTA) updates, which fails to validate the current version against the new version. This flaw permits downgrading to earlier firmware versions which may have known vulnerabilities. Attackers can exploit this weakness even when bootloaders are locked and without a factory reset, thus compromising user data. This vulnerability can be exploited by a Man-in-the-Middle (MiTM) attacker during the update process, given that the transactions lack Transport Layer Security (TLS). Additionally, an adversary with physical access can utilize tools such as 'adb sideload' to execute a downgrade by rebooting the device into recovery mode.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.