CVE-2017-5947: Medium severity oxygenos vulnerability
An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in turn could allow for downgrading partitions such as the Android Bootloader.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5947?
CVE-2017-5947 has been evaluated as a high severity vulnerability due to the potential for unauthorized device control.
What systems are affected by CVE-2017-5947?
CVE-2017-5947 affects OnePlus One, X, 2, 3, 3T, and 5 devices running OxygenOS 5.0 and earlier.
How do I fix CVE-2017-5947?
To mitigate CVE-2017-5947, users should update their devices to the latest version of OxygenOS.
Can CVE-2017-5947 be exploited remotely?
CVE-2017-5947 requires physical access to the device, thus it cannot be exploited remotely.
What is the risk associated with CVE-2017-5947?
The risk associated with CVE-2017-5947 includes potential unauthorized access and modification of device firmware.