CVE-2017-8851 affects OnePlus One and X devices, stemming from a lenient updater-script and shared verification keys/system properties that allow attackers to install incorrect Over-The-Air (OTA) updates across these models. This vulnerability, rated Medium severity (CVSS 5.9), can be exploited via Man-in-the-Middle attacks during the unencrypted update process or physically through ADB sideloading in recovery mode. Successful exploitation could lead to an expanded attack surface, unpatched vulnerabilities, or render the device unusable, requiring a factory reset. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:oneplus:oxygenos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.