SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-19412

Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability.

MEDIUM 4.6EPSS 0.21%

Does this matter?

Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.

Description

Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-frp-en.

CVSS 3.1
4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
0.21% probability · 12th percentile
CISA KEV
Not listed
Affected
huawei/alp-al00b firmware · huawei/alp-l09 firmware · huawei/alp-l29 firmware · huawei/anne-al00 firmware · huawei/bla-al00b firmware · huawei/bla-l09c firmware · huawei/bla-l29c firmware · huawei/berkeley-al20 firmware · huawei/berkeley-l09 firmware · huawei/emily-l29c firmware · huawei/figo-l03 firmware · huawei/figo-l21 firmware · huawei/figo-l23 firmware · huawei/figo-l31 firmware · huawei/florida-l03 firmware · huawei/florida-l21 firmware · huawei/florida-l22 firmware · huawei/florida-l23 firmware · huawei/p smart firmware · huawei/y7s firmware · +8 more
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.