CVE-2019-5283
Description
There is Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions earlier than Emily-AL00A 9.0.0.167 (C00E81R1P21T8). When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and can perform some operations to access the setting page. As a result, the FRP function is bypassed.
Risk Information
Base Score
4.6
MODERATE
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.027
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.130 | NCM |
| Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.128 | NCM |
| Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.121 | NCM |
| Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.120 | NCM |
| Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.109 | NCM |
| Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.0.1.16(c00) | NCM |
| Vulnerabilities CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware emily-al00a_9.0.0.167(c00e81r1p21t8) | NCM |
| Vulnerabilities CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 10.0.0.156(c00e156r1p4) | NCM |
| Vulnerabilities CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 9.1.0.333(c00e333r1p1t8) | NCM |
| Vulnerabilities CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.171(c00) | NCM |
| CVE-2019-5283 | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234