PT-2020-10157 · Huawei · Huawei Y7S+4

Published

2020-06-08

·

Updated

2020-07-08

·

CVE-2019-19412

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Huawei smart phones versions earlier than 8.0.0.168 Huawei smart phones versions earlier than 9.0.0.177 Huawei smart phones versions earlier than 9.0.0.181 Huawei smart phones versions earlier than 9.0.0.201 Huawei smart phones versions earlier than 9.1.0.130 ALP-AL00B versions earlier than 9.0.0.181 ALP-L09 versions earlier than 9.0.0.201 ALP-L29 versions earlier than 9.0.0.177 ALP-L29 versions earlier than 9.0.0.195 Anne-AL00 versions earlier than 8.0.0.168 BLA-AL00B versions earlier than 9.0.0.181 BLA-L09C versions earlier than 9.0.0.177 BLA-L09C versions earlier than 9.0.0.206 BLA-L29C versions earlier than 9.0.0.179 BLA-L29C versions earlier than 9.0.0.194 BLA-L29C versions earlier than 9.0.0.206 BLA-L29C versions earlier than 9.0.0.210 Berkeley-AL20 versions earlier than 9.0.0.156 Berkeley-L09 versions earlier than 8.0.0.172 Berkeley-L09 versions earlier than 8.0.0.173 Emily-L29C versions earlier than 9.0.0.159 Emily-L29C versions earlier than 9.0.0.160 Emily-L29C versions earlier than 9.0.0.165 Emily-L29C versions earlier than 9.0.0.168 Emily-L29C versions earlier than 9.0.0.196 Figo-L03 versions earlier than 9.1.0.130 Figo-L21 versions earlier than 9.1.0.130 Figo-L23 versions earlier than 9.1.0.130 Figo-L31 versions earlier than 9.1.0.130 Florida-L03 versions earlier than 9.1.0.121 Florida-L21 versions earlier than 8.0.0.129 Florida-L21 versions earlier than 8.0.0.131 Florida-L21 versions earlier than 8.0.0.132 Florida-L22 versions earlier than 8.0.0.132 Florida-L23 versions earlier than 8.0.0.144 HUAWEI P smart versions earlier than 9.1.0.130 HUAWEI P smart, HUAWEI Y7s versions earlier than 9.1.0.124 HUAWEI P20 lite versions earlier than 8.0.0.148 HUAWEI P20 lite versions earlier than 8.0.0.155 HUAWEI P20 lite versions earlier than 8.0.0.156 HUAWEI P20 lite versions earlier than 8.0.0.157 HUAWEI nova 3e, HUAWEI P20 lite versions earlier than 8.0.0.147 HUAWEI nova 3e, HUAWEI P20 lite versions earlier than 8.0.0.148 HUAWEI nova 3e, HUAWEI P20 lite versions earlier than 8.0.0.160 HUAWEI nova 3e, HUAWEI P20 lite versions earlier than 8.0.0.168 HUAWEI nova 3e, HUAWEI P20 lite versions earlier than 8.0.0.172 Honor View 10 versions earlier than 9.0.0.202 Leland-AL00A versions earlier than 8.0.0.182 Leland-L21A versions earlier than 8.0.0.135 Leland-L21A versions earlier than 9.1.0.118 Leland-L22A versions earlier than 9.1.0.118 Leland-L22C versions earlier than 9.1.0.118 Leland-L31A versions earlier than 8.0.0.139
Description The issue is related to a Factory Reset Protection (FRP) bypass security vulnerability in Huawei smart phones. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login to the Talkback mode and perform some operations to install a third-party application.
Recommendations For ALP-AL00B versions earlier than 9.0.0.181, update to version 9.0.0.181 or later. For ALP-L09 versions earlier than 9.0.0.201, update to version 9.0.0.201 or later. For ALP-L29 versions earlier than 9.0.0.177, update to version 9.0.0.177 or later. For ALP-L29 versions earlier than 9.0.0.195, update to version 9.0.0.195 or later. For Anne-AL00 versions earlier than 8.0.0.168, update to version 8.0.0.168 or later. For BLA-AL00B versions earlier than 9.0.0.181, update to version 9.0.0.181 or later. For BLA-L09C versions earlier than 9.0.0.177, update to version 9.0.0.177 or later. For BLA-L09C versions earlier than 9.0.0.206, update to version 9.0.0.206 or later. For BLA-L29C versions earlier than 9.0.0.179, update to version 9.0.0.179 or later. For BLA-L29C versions earlier than 9.0.0.194, update to version 9.0.0.194 or later. For BLA-L29C versions earlier than 9.0.0.206, update to version 9.0.0.206 or later. For BLA-L29C versions earlier than 9.0.0.210, update to version 9.0.0.210 or later. For Berkeley-AL20 versions earlier than 9.0.0.156, update to version 9.0.0.156 or later. For Berkeley-L09 versions earlier than 8.0.0.172, update to version 8.0.0.172 or later. For Berkeley-L09 versions earlier than 8.0.0.173, update to version 8.0.0.173 or later. For Emily-L29C versions earlier than 9.0.0.159, update to version 9.0.0.159 or later. For Emily-L29C versions earlier than 9.0.0.160, update to version 9.0.0.160 or later. For Emily-L29C versions earlier than 9.0.0.165, update to version 9.0.0.165 or later. For Emily-L29C versions earlier than 9.0.0.168, update to version 9.0.0.168 or later. For Emily-L29C versions earlier than 9.0.0.196, update to version 9.0.0.196 or later. For Figo-L03 versions earlier than 9.1.0.130, update to version 9.1.0.130 or later. For Figo-L21 versions earlier than 9.1.0.130, update to version 9.1.0.130 or later. For Figo-L23 versions earlier than 9.1.0.130, update to version 9.1.0.130 or later. For Figo-L31 versions earlier than 9.1.0.130, update to version 9.1.0.130 or later. For Florida-L03 versions earlier than 9.1.0.121, update to version 9.1.0.121 or later. For Florida-L21 versions earlier than 8.0.0.129, update to version 8.0.0.129 or later. For Florida-L21 versions earlier than 8.0.0.131, update to version 8.0.0.131 or later. For Florida-L21 versions earlier than 8.0.0.132, update to version 8.0.0.132 or later. For Florida-L22 versions earlier than 8.0.0.132, update to version 8.0.0.132 or later. For Florida-L23 versions earlier than 8.0.0.144, update to version 8.0.0.144 or later. For HUAWEI P smart versions earlier than 9.1.0.130, update to version 9.1.0.130 or later. For HUAWEI P smart, HUAWEI Y7s versions earlier than 9.1.0.124, update to version 9.1.0.124 or later. For HUAWEI P20 lite versions earlier than 8.0.0.148, update to version 8.0.0.148 or later. For HUAWEI P20 lite versions earlier than 8.0.0.155, update to version 8.0.0.155 or later. For HUAWEI P20 lite versions earlier than 8.0.0.156, update to version 8.0.0.156 or later. For HUAWEI P20 lite versions earlier than 8.0.0.157, update to version 8.0.0.157 or later. For HUAWEI nova 3e, HUAWEI P20 lite versions earlier than 8.0.0.147, update to version 8.0.0.147 or later. For HUAWEI nova 3e, HUAWEI P20 lite versions earlier than 8.0.0.148, update to version 8.0.0.148 or later. For HUAWEI nova 3e, HUAWEI P20 lite versions earlier than 8.0.0.160, update to version 8.0.0.160 or later. For HUAWEI nova 3e, HUAWEI P20 lite versions earlier than 8.0.0.168, update to version 8.0.0.168 or later. For HUAWEI nova 3e, HUAWEI P20 lite versions earlier than 8.0.0.172, update to version 8.0.0.172 or later. For Honor View 10 versions earlier than 9.0.0.202, update to version 9.0.0.202 or later. For Leland-AL00A versions earlier than 8.0.0.182, update to version 8.0.0.182 or later. For Leland-L21A versions earlier than 8.0.0.135, update to version 8.0.0.135 or later. For Leland-L21A versions earlier than 9.1.0.118, update to version 9.1.0.118 or later. For Leland-L22A versions earlier than 9.1.0.118, update to version 9.1.0.118 or later. For Leland-L22C versions earlier than 9.1.0.118, update to version 9.1.0.118 or later. For Leland-L31A versions earlier than 8.0.0.139, update to version 8.0.0.139 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-19412

Affected Products

Huawei P Smart
Huawei P20 Lite
Huawei Y7S
Huawei Nova 3E
Honor View 10