Factory Reset Protection Bypass in Huawei P20 Smartphones
CVE-2019-5283

4.6MEDIUM

Key Information:

Vendor
Huawei
Status
Vendor
CVE Published:
4 June 2019

Summary

A security vulnerability exists within the Factory Reset Protection (FRP) mechanism in Huawei P20 smartphones, allowing potential attackers to bypass the FRP feature. This can be exploited by accessing the device through Talkback mode during the reconfiguration process, enabling unauthorized users to access sensitive settings. It is crucial for users of affected versions to apply the necessary updates to mitigate this risk.

Affected Version(s)

P20 Versions earlier than Emily-AL00A 9.0.0.167(C00E81R1P21T8)

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.