MEDIUM · 4.6

CVE-2019-19412

Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the T...

Vulnerability Description

Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-frp-en.

CVSS Score

4.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
HuaweiAlp-Al00B Firmware< 9.0.0.181\(c00e87r2p20t8\)
HuaweiAlp-Al00B-
HuaweiAlp-L09 Firmware< 9.0.0.201\(c432e4r1p9\)
HuaweiAlp-L09-
HuaweiAlp-L29 Firmware< 9.0.0.177\(c185e2r1p12t8\)
HuaweiAlp-L29-
HuaweiAnne-Al00 Firmware< 8.0.0.168\(c00\)
HuaweiAnne-Al00-
HuaweiBla-Al00B Firmware< 9.0.0.181\(c00e88r2p15t8\)
HuaweiBla-Al00B-
HuaweiBla-L09C Firmware< 9.0.0.177\(c185e2r1p13t8\)
HuaweiBla-L09C-
HuaweiBla-L29C Firmware< 9.0.0.179\(c576e2r1p7t8\)
HuaweiBla-L29C-
HuaweiBerkeley-Al20 Firmware< 9.0.0.156\(c00e156r2p14t8\)
HuaweiBerkeley-Al20-
HuaweiBerkeley-L09 Firmware< 8.0.0.172\(c432\)
HuaweiBerkeley-L09-
HuaweiEmily-L29C Firmware< 9.0.0.159\(c185e2r1p12t8\)
HuaweiEmily-L29C-

References

FAQ

What is CVE-2019-19412?

CVE-2019-19412 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the T...

How severe is CVE-2019-19412?

CVE-2019-19412 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-19412?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Alp-Al00B Firmware, Huawei Alp-Al00B, Huawei Alp-L09 Firmware, Huawei Alp-L09, Huawei Alp-L29 Firmware.