An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the attack surface, and allows for remote exploitation of other vulnerabilities such as CVE-2017-5948, CVE-2017-8850, and CVE-2017-8851.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-05-11T18:00:00
Updated: 2024-08-06T03:21:51.632Z
Reserved: 2017-05-08T00:00:00
Link: CVE-2016-10370
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-05-11T18:29:00.173
Modified: 2024-11-21T02:43:52.093
Link: CVE-2016-10370
Redhat
No data.