CVE-2017-5622
—CVSS 3.0
5.9 medium
EPSS
<1%p23
Published
()
Modified
Description
With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information.
- Vendors
- oneplus
- Products
- oxygenos
- Weakness
- CWE-276
- Vector
- CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.