Vulnerability Details CVE-2019-5283
There is Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions earlier than Emily-AL00A 9.0.0.167 (C00E81R1P21T8). When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and can perform some operations to access the setting page. As a result, the FRP function is bypassed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.1%
CVSS Severity
CVSS v3 Score 4.6
CVSS v2 Score 2.1
Products affected by CVE-2019-5283
-
-
cpe:2.3:o:huawei:p20_firmware:-
-
cpe:2.3:o:huawei:p20_firmware:10.0.0.156(c00e156r1p4)
-
cpe:2.3:o:huawei:p20_firmware:10.0.0.162(c00e156r1p4)
-
cpe:2.3:o:huawei:p20_firmware:8.0.1.16(c00)
-
cpe:2.3:o:huawei:p20_firmware:8.1.0.109
-
cpe:2.3:o:huawei:p20_firmware:8.1.0.120
-
cpe:2.3:o:huawei:p20_firmware:8.1.0.121
-
cpe:2.3:o:huawei:p20_firmware:8.1.0.128
-
cpe:2.3:o:huawei:p20_firmware:8.1.0.130
-
cpe:2.3:o:huawei:p20_firmware:8.1.0.171(c00)
-
cpe:2.3:o:huawei:p20_firmware:9.1.0.312(c00e312r1p1t8)
-
cpe:2.3:o:huawei:p20_firmware:9.1.0.333(c00e333r1p1t8)