ZeroHour

CVE-2017-5622

CVSS 3.0
5.9 medium
EPSS
<1%p23
Published
()
Modified
Description

With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information.

Vendors
oneplus
Products
oxygenos
Weakness
CWE-276
Vector
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.