CVE-2019-5220

4.6MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
10 July 2019

Summary

There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Successful exploit could allow the attacker bypass the FRP protection. Affected products: Mate 20 X, versions earlier than Ever-AL00B 9.0.0.200(C00E200R2P1); Mate 20, versions earlier than Hima-AL00B/Hima-TL00B 9.0.0.200(C00E200R2P1); Honor Magic 2, versions earlier than Tony-AL00B/Tony-TL00B 9.0.0.182(C00E180R2P2).

Affected Version(s)

Honor Magic 2 Versions earlier than Tony-AL00B/Tony-TL00B 9.0.0.182(C00E180R2P2)

Mate 20 Versions earlier than Hima-AL00B/Hima-TL00B 9.0.0.200(C00E200R2P1)

Mate 20 X Versions earlier than Ever-AL00B 9.0.0.200(C00E200R2P1)

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.