Factory Reset Protection Bypass in Huawei P20 Smartphones
CVE-2019-5306
4.6MEDIUM
Summary
A security vulnerability exists in Huawei P20 smartphones that allows attackers to bypass the Factory Reset Protection (FRP) feature. This can be exploited when a device is reconfigured via the FRP mechanism. An unauthorized user can execute a specific sequence of actions that leads to the deletion of the activation lock, effectively circumventing the FRP. This leaves the device vulnerable to unauthorized access, compromising the security of personal information stored on it.
Affected Version(s)
P20 The versions before Emily-AL00A 9.0.0.167(C00E81R1P21T8)
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved