CVE-2019-5306

Description

There is a Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions before Emily-AL00A 9.0.0.167(C00E81R1P21T8). When re-configuring the mobile phone using the FRP function, an attacker can delete the activation lock after a series of operations. As a result, the FRP function is bypassed and the attacker gains access to the smartphone.

Risk Information

Base Score
4.6
MODERATE
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.027

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.130NCM
Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.128NCM
Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.121NCM
Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.120NCM
Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.109NCM
Vulnerabilities CVE-2018-7987 ,CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.0.1.16(c00)NCM
Vulnerabilities CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware emily-al00a_9.0.0.167(c00e81r1p21t8)NCM
Vulnerabilities CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 10.0.0.156(c00e156r1p4)NCM
Vulnerabilities CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 9.1.0.333(c00e333r1p1t8)NCM
Vulnerabilities CVE-2019-5211 ,CVE-2019-5212 ,CVE-2019-5283 ,CVE-2019-5306 are affected in p20_firmware 8.1.0.171(c00)NCM
CVE-2019-5306NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234