CVE-2017-11105: Critical severity oneplus primary bootloader vulnerability
The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that partition to disable signature validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11105?
CVE-2017-11105 has been assigned a high severity rating due to its potential to allow attackers to bypass signature validation on the affected devices.
How do I fix CVE-2017-11105?
To fix CVE-2017-11105, you should update the OnePlus 2 firmware from the official OnePlus website to a version that addresses this vulnerability.
What devices are affected by CVE-2017-11105?
CVE-2017-11105 specifically affects the OnePlus 2 model due to vulnerabilities in its Primary Bootloader.
What is the impact of CVE-2017-11105?
The impact of CVE-2017-11105 allows an attacker to disable signature validation, potentially leading to unauthorized code execution on the device.
Is there a workaround for CVE-2017-11105?
There are no documented workarounds for CVE-2017-11105; applying a firmware update is the recommended solution.