CVE-2019-19412
Last modified
CVE-2019-19412 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-frp-en.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Alp-Al00b Firmware | < 9.0.0.181\(c00e87r2p20t8\) |
| Huawei | Alp-L09 Firmware | < 9.0.0.201\(c432e4r1p9\) |
| Huawei | Alp-L29 Firmware | < 9.0.0.177\(c185e2r1p12t8\) |
| Huawei | Alp-L29 Firmware | < 9.0.0.195\(c636e2r1p12\) |
| Huawei | Anne-Al00 Firmware | < 8.0.0.168\(c00\) |
| Huawei | Bla-Al00b Firmware | < 9.0.0.181\(c00e88r2p15t8\) |
| Huawei | Bla-L09c Firmware | < 9.0.0.177\(c185e2r1p13t8\) |
| Huawei | Bla-L09c Firmware | < 9.0.0.206\(c432e4r1p11\) |
| Huawei | Bla-L29c Firmware | < 9.0.0.179\(c576e2r1p7t8\) |
| Huawei | Bla-L29c Firmware | < 9.0.0.194\(c185e2r1p13\) |
| Huawei | Bla-L29c Firmware | < 9.0.0.206\(c432e4r1p11\) |
| Huawei | Bla-L29c Firmware | < 9.0.0.210\(c635e4r1p13\) |
| Huawei | Berkeley-Al20 Firmware | < 9.0.0.156\(c00e156r2p14t8\) |
| Huawei | Berkeley-L09 Firmware | < 8.0.0.172\(c432\) |
| Huawei | Berkeley-L09 Firmware | < 8.0.0.173\(c636\) |
| Huawei | Emily-L29c Firmware | < 9.0.0.159\(c185e2r1p12t8\) |
| Huawei | Emily-L29c Firmware | < 9.0.0.159\(c461e2r1p11t8\) |
| Huawei | Emily-L29c Firmware | < 9.0.0.160\(c432e7r1p11t8\) |
| Huawei | Emily-L29c Firmware | < 9.0.0.165\(c605e2r1p12\) |
| Huawei | Emily-L29c Firmware | < 9.0.0.168\(c636e7r1p13t8\) |
| Huawei | Emily-L29c Firmware | < 9.0.0.168\(c782e3r1p11t8\) |
| Huawei | Emily-L29c Firmware | < 9.0.0.196\(c635e2r1p11t8\) |
| Huawei | Figo-L03 Firmware | < 9.1.0.130\(c605e6r1p5t8\) |
| Huawei | Figo-L21 Firmware | < 9.1.0.130\(c185e6r1p5t8\) |
| Huawei | Figo-L21 Firmware | < 9.1.0.130\(c635e6r1p5t8\) |
| Huawei | Figo-L23 Firmware | < 9.1.0.130\(c605e6r1p5t8\) |
| Huawei | Figo-L31 Firmware | < 9.1.0.130\(c432e8r1p5t8\) |
| Huawei | Florida-L03 Firmware | < 9.1.0.121\(c605e5r1p1t8\) |
| Huawei | Florida-L21 Firmware | < 8.0.0.129\(c605\) |
| Huawei | Florida-L21 Firmware | < 8.0.0.131\(c432\) |
| Huawei | Florida-L21 Firmware | < 8.0.0.132\(c185\) |
| Huawei | Florida-L22 Firmware | < 8.0.0.132\(c636\) |
| Huawei | Florida-L23 Firmware | < 8.0.0.144\(c605\) |
| Huawei | P Smart Firmware | < 9.1.0.130\(c185e6r1p5t8\) |
| Huawei | P Smart Firmware | < 9.1.0.130\(c605e6r1p5t8\) |
| Huawei | P Smart Firmware | < 9.1.0.124\(c636e6r1p5t8\) |
| Huawei | Y7s Firmware | < 9.1.0.124\(c636e6r1p5t8\) |
| Huawei | P20 Lite Firmware | < 8.0.0.148\(c635\) |
| Huawei | P20 Lite Firmware | < 8.0.0.155\(c185\) |
| Huawei | P20 Lite Firmware | < 8.0.0.155\(c605\) |
| Huawei | P20 Lite Firmware | < 8.0.0.156\(c605\) |
| Huawei | P20 Lite Firmware | < 8.0.0.157\(c432\) |
| Huawei | Nova 3e Firmware | < 8.0.0.147\(c461\) |
| Huawei | Nova 3e Firmware | < 8.0.0.148\(zafc185\) |
| Huawei | Nova 3e Firmware | < 8.0.0.160\(c185\) |
| Huawei | Nova 3e Firmware | < 8.0.0.160\(c605\) |
| Huawei | Nova 3e Firmware | < 8.0.0.168\(c432\) |
| Huawei | Nova 3e Firmware | < 8.0.0.172\(c636\) |
| Huawei | P20 Lite Firmware | < 8.0.0.147\(c461\) |
| Huawei | P20 Lite Firmware | < 8.0.0.148\(zafc185\) |
Showing 50 of 61 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-19412?
How severe is CVE-2019-19412?
How do I fix CVE-2019-19412?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19396illumos, as used in OmniOS Community Edition before r151030y…7.5
- CVE-2019-19397There is a weak algorithm vulnerability in some Huawei produ…7.5
- CVE-2019-19398M5 lite 10 with versions of 8.0.0.182(C00) have an insuffici…9.8
- CVE-2019-1940A vulnerability in the Web Services Management Agent (WSMA) …5.9
- CVE-2019-1941A vulnerability in the web-based management interface of Cis…6.1
- CVE-2019-19411USG9500 with versions of V500R001C30SPC100, V500R001C30SPC20…3.7
- CVE-2019-19413There is an integer overflow vulnerability in LDAP client of…7.5
- CVE-2019-19414There is an integer overflow vulnerability in LDAP server of…7.5
- CVE-2019-19415The SIP module of some Huawei products have a denial of serv…7.5
- CVE-2019-19416The SIP module of some Huawei products have a denial of serv…7.5
- CVE-2019-19417The SIP module of some Huawei products have a denial of serv…7.5
- CVE-2019-1942A vulnerability in the sponsor portal web interface for Cisc…4.3
Are you affected by CVE-2019-19412?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
