漏洞关键信息 Identifier: CVE-2017-5947 Severity: High Affected Devices: OnePlus One, OnePlus X, OnePlus 2, OnePlus 3, OnePlus 3T, OnePlus 5 Vulnerable Version: OxygenOS 5.0 and below Technical Details: - OxygenOS in OnePlus devices allows booting into Qualcomm EDL through ADB or hardware key combination. - Leaked Firehose programmers can be exploited to downgrade critical partitions, enabling old vulnerability exploitation. Timeline: - 19-Jan-17: Reported - 09-Feb-17: CVE ID requested - 10-Feb-17: CVE-2017-5947 assigned - 01-Mar-17: Added as ALEPH-2017007 - 22-Jan-18: Public disclosure Posts: - Series of articles on exploiting Qualcomm EDL programmers by Roei Hay & Noam Hadad Credit: Roei Hay of Aleph Research, HCL Software