漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
N/A
漏洞信息
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenient 'updater-script' in OTAs that does not check that the current version is lower than or equal to the given image's. Downgrades can occur even on locked bootloaders and without triggering a factory reset, allowing for exploitation of now-patched vulnerabilities with access to user data. This vulnerability can be exploited by a Man-in-the-Middle (MiTM) attacker targeting the update process. This is possible because the update transaction does not occur over TLS (CVE-2016-10370). In addition, a physical attacker can reboot the phone into recovery, and then use 'adb sideload' to push the OTA (on OnePlus 3/3T 'Secure Start-up' must be off).
漏洞信息
N/A
漏洞
N/A
漏洞
多款OnePlus产品OxygenOS和HydrogenOS OTAs 安全漏洞
漏洞信息
OnePlus One等都是中国一加科技(OnePlus)公司的智能手机。OxygenOS和HydrogenOS都是其自带的操作系统。HydrogenOS OTAs是HydrogenOS中的一个系统更新应用程序。 多款OnePlus产品中的OxygenOS和HydrogenOS OTAs存在安全漏洞。攻击者可利用该漏洞实施降级攻击。以下产品受到影响:OnePlus One;OnePlus X;OnePlus 2;OnePlus 3;OnePlus 3T。
漏洞信息
N/A
漏洞
N/A