vendor:
Android Bootloader
by:
Roee Hay / Aleph Research, HCL Technologies
7,8
CVSS
HIGH
Kernel Command-Line Injection
94
CWE
Product Name: Android Bootloader
Affected Version From: Vulnerable versions of the Motorola Android Bootloader (ABOOT)
Affected Version To: Vulnerable versions of the Motorola Android Bootloader (ABOOT)
Patch Exists: YES
Related CWE: CVE-2016-10277
CPE: o:motorola:android_bootloader
Metasploit:
https://www.rapid7.com/db/vulnerabilities/debian-cve-2017-1000363/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2017-1000363/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2017-1000363/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2017-1000363/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-10277/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Android
2017
initroot: Motorola Bootloader Kernel Cmdline Injection Secure Boot & Device Locking Bypass (CVE-2016-10277)
Vulnerable versions of the Motorola Android Bootloader (ABOOT) allow for kernel command-line injection. Using a proprietary fastboot OEM command, only available in the Motorola ABOOT, an adversary can inject, through USB, a parameter named initrd which allows them to force the Linux kernel to populate initramfs into rootfs from a specified physical address. This can be abused to place a malicious initramfs at a known physical address, named SCRATCH_ADDR, and exploit the vulnerability to gain unconfined root shell. However, the initramfs payload must be re-exploited on every reboot.
Mitigation:
The vulnerability can be mitigated by disabling the fastboot OEM command, or by disabling the download functionality in the ABOOT.