CVE-2019-19412

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/06/2020
Last modified:
08/07/2020

Description

Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-frp-en.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:alp-al00b_firmware:*:*:*:*:*:*:*:* 9.0.0.181\(c00e87r2p20t8\) (excluding)
cpe:2.3:h:huawei:alp-al00b:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:alp-l09_firmware:*:*:*:*:*:*:*:* 9.0.0.201\(c432e4r1p9\) (excluding)
cpe:2.3:h:huawei:alp-l09:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:alp-l29_firmware:*:*:*:*:*:*:*:* 9.0.0.177\(c185e2r1p12t8\) (excluding)
cpe:2.3:h:huawei:alp-l29:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:alp-l29_firmware:*:*:*:*:*:*:*:* 9.0.0.195\(c636e2r1p12\) (excluding)
cpe:2.3:h:huawei:alp-l29:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:anne-al00_firmware:*:*:*:*:*:*:*:* 8.0.0.168\(c00\) (excluding)
cpe:2.3:h:huawei:anne-al00:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:bla-al00b_firmware:*:*:*:*:*:*:*:* 9.0.0.181\(c00e88r2p15t8\) (excluding)
cpe:2.3:h:huawei:bla-al00b:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:bla-l09c_firmware:*:*:*:*:*:*:*:* 9.0.0.177\(c185e2r1p13t8\) (excluding)
cpe:2.3:h:huawei:bla-l09c:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:bla-l09c_firmware:*:*:*:*:*:*:*:* 9.0.0.206\(c432e4r1p11\) (excluding)