CVE-2019-19412
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/06/2020
Last modified:
08/07/2020
Description
Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-frp-en.
Impact
Base Score 3.x
4.60
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:huawei:alp-al00b_firmware:*:*:*:*:*:*:*:* | 9.0.0.181\(c00e87r2p20t8\) (excluding) | |
cpe:2.3:h:huawei:alp-al00b:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:alp-l09_firmware:*:*:*:*:*:*:*:* | 9.0.0.201\(c432e4r1p9\) (excluding) | |
cpe:2.3:h:huawei:alp-l09:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:alp-l29_firmware:*:*:*:*:*:*:*:* | 9.0.0.177\(c185e2r1p12t8\) (excluding) | |
cpe:2.3:h:huawei:alp-l29:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:alp-l29_firmware:*:*:*:*:*:*:*:* | 9.0.0.195\(c636e2r1p12\) (excluding) | |
cpe:2.3:h:huawei:alp-l29:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:anne-al00_firmware:*:*:*:*:*:*:*:* | 8.0.0.168\(c00\) (excluding) | |
cpe:2.3:h:huawei:anne-al00:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:bla-al00b_firmware:*:*:*:*:*:*:*:* | 9.0.0.181\(c00e88r2p15t8\) (excluding) | |
cpe:2.3:h:huawei:bla-al00b:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:bla-l09c_firmware:*:*:*:*:*:*:*:* | 9.0.0.177\(c185e2r1p13t8\) (excluding) | |
cpe:2.3:h:huawei:bla-l09c:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:bla-l09c_firmware:*:*:*:*:*:*:*:* | 9.0.0.206\(c432e4r1p11\) (excluding) |
To consult the complete list of CPE names with products and versions, see this page