Oneplus 3t
Vendor:
First CVE: Jan 23, 2017 · Active for 9 years
10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Oneplus 3t over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2017
9 years ago
Most Recent CVE
Mar 29, 2018
3,041 days ago
CVE Severity & Scoring
Oneplus 3t10 CVEs
60%
20%
20%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (60.0%)
Unknown0 (0.0%)
Physical4 (40.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (70.0%)
High3 (30.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None8 (80.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5554HIGH An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authenticatio | Jan 23, 2017 | 8.1 | 27 | NO | NO |
CVE-2017-5626CRITICAL OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to lock/unlock the bootloader, disregarding | Mar 12, 2017 | 9.8 | 26 | NO | NO |
CVE-2017-5624CRITICAL An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform with dm-verity disabled, by iss | Mar 12, 2017 | 9.8 | 25 | NO | NO |
CVE-2016-10370HIGH An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of ar | May 11, 2017 | 7.5 | 22 | NO | NO |
CVE-2017-5622MEDIUM With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical | Mar 26, 2017 | 5.9 | 22 | NO | NO |
CVE-2017-8850MEDIUM An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both ROMs use the same OTA verificatio | May 11, 2017 | 5.9 | 21 | NO | NO |
CVE-2017-5947MEDIUM An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode | Mar 29, 2018 | 6.8 | 18 | NO | NO |
CVE-2017-5948MEDIUM An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenient 'updater-script' in OTAs that | May 11, 2017 | 5.9 | 17 | NO | NO |
CVE-2017-5625MEDIUM In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (exc | Apr 25, 2017 | 4.6 | 17 | NO | NO |
CVE-2017-5623MEDIUM An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm | Mar 19, 2017 | 6.6 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Oneplus 3t
Top CWEs
Versions
No cataloged versions.