CVE Database
/

CVE-2017-5622

Back to search

CVE-2017-5622

Published: Mar 26, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information.

VendorProductVersions

n/a

n/a

affected
n/a

References

97092
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now