Advisory Published
Updated

CVE-2019-19412

First published: Mon Jun 08 2020(Updated: )

Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-frp-en.

Credit: psirt@huawei.com

Affected SoftwareAffected VersionHow to fix
Huawei Alp-al00b Firmware<9.0.0.181\(c00e87r2p20t8\)
Huawei ALP-AL00B
Huawei Alp-l09 Firmware<9.0.0.201\(c432e4r1p9\)
Huawei ALP-L09
Huawei Alp-l29 Firmware<9.0.0.177\(c185e2r1p12t8\)
Huawei Alp-l29
Huawei Alp-l29 Firmware<9.0.0.195\(c636e2r1p12\)
Huawei Anne-al00 Firmware<8.0.0.168\(c00\)
Huawei Anne-al00
Google Android<9.0.0.181\(c00e88r2p15t8\)
Google Android
Huawei Bla-l09c Firmware<9.0.0.177\(c185e2r1p13t8\)
Huawei Bla-l09c
Huawei Bla-l09c Firmware<9.0.0.206\(c432e4r1p11\)
Huawei Bla-l29c Firmware<9.0.0.179\(c576e2r1p7t8\)
Apple tvOS
Huawei Bla-l29c Firmware<9.0.0.194\(c185e2r1p13\)
Huawei Bla-l29c Firmware<9.0.0.206\(c432e4r1p11\)
Huawei Bla-l29c Firmware<9.0.0.210\(c635e4r1p13\)
Huawei Berkeley-al20 Firmware<9.0.0.156\(c00e156r2p14t8\)
Huawei Berkeley-AL20
Huawei Berkeley-l09 Firmware<8.0.0.172\(c432\)
Apple tvOS
Huawei Berkeley-l09 Firmware<8.0.0.173\(c636\)
Huawei Emily-l29c Firmware<9.0.0.159\(c185e2r1p12t8\)
Huawei Emily-l29c
Huawei Emily-l29c Firmware<9.0.0.159\(c461e2r1p11t8\)
Huawei Emily-l29c Firmware<9.0.0.160\(c432e7r1p11t8\)
Huawei Emily-l29c Firmware<9.0.0.165\(c605e2r1p12\)
Huawei Emily-l29c Firmware<9.0.0.168\(c636e7r1p13t8\)
Huawei Emily-l29c Firmware<9.0.0.168\(c782e3r1p11t8\)
Huawei Emily-l29c Firmware<9.0.0.196\(c635e2r1p11t8\)
Huawei Figo-l03 Firmware<9.1.0.130\(c605e6r1p5t8\)
Huawei Figo-l03
Huawei Figo-l21 Firmware<9.1.0.130\(c185e6r1p5t8\)
Huawei Figo-l21
Huawei Figo-l21 Firmware<9.1.0.130\(c635e6r1p5t8\)
Apple High Sierra<9.1.0.130\(c605e6r1p5t8\)
Apple tvOS
Apple iOS<9.1.0.130\(c432e8r1p5t8\)
Apple tvOS
Huawei Florida-l03 Firmware<9.1.0.121\(c605e5r1p1t8\)
Huawei Florida-l03
Apple macOS Mojave<8.0.0.129\(c605\)
Apple High Sierra
Apple macOS Mojave<8.0.0.131\(c432\)
Apple macOS Mojave<8.0.0.132\(c185\)
Apple watchOS<8.0.0.132\(c636\)
Apple watchOS
Apple iOS<8.0.0.144\(c605\)
Apple High Sierra
Apple Sierra<9.1.0.130\(c185e6r1p5t8\)
Apple Sierra
Apple Sierra<9.1.0.130\(c605e6r1p5t8\)
Apple Sierra<9.1.0.124\(c636e6r1p5t8\)
Huawei Y7s Firmware<9.1.0.124\(c636e6r1p5t8\)
Huawei Y7s
Huawei P20 Lite Firmware<8.0.0.148\(c635\)
Huawei P20 Lite
Huawei P20 Lite Firmware<8.0.0.155\(c185\)
Huawei P20 Lite Firmware<8.0.0.155\(c605\)
Huawei P20 Lite Firmware<8.0.0.156\(c605\)
Huawei P20 Lite Firmware<8.0.0.157\(c432\)
Huawei Nova 3e Firmware<8.0.0.147\(c461\)
Huawei Nova 3e
Huawei Nova 3e Firmware<8.0.0.148\(zafc185\)
Huawei Nova 3e Firmware<8.0.0.160\(c185\)
Huawei Nova 3e Firmware<8.0.0.160\(c605\)
Huawei Nova 3e Firmware<8.0.0.168\(c432\)
Huawei Nova 3e Firmware<8.0.0.172\(c636\)
Huawei P20 Lite Firmware<8.0.0.147\(c461\)
Huawei P20 Lite Firmware<8.0.0.148\(zafc185\)
Huawei P20 Lite Firmware<8.0.0.160\(c185\)
Huawei P20 Lite Firmware<8.0.0.160\(c605\)
Huawei P20 Lite Firmware<8.0.0.168\(c432\)
Huawei P20 Lite Firmware<8.0.0.172\(c636\)
Apple High Sierra<9.0.0.202\(c567e6r1p12t8\)
Apple High Sierra
Huawei Leland-al00a Firmware<8.0.0.182\(c00\)
Huawei Leland-al00a
Apple macOS Mojave<8.0.0.135\(c185\)
Apple tvOS
Apple macOS Mojave<9.1.0.118\(c636e4r1p1t8\)
Huawei Leland-l22a Firmware<9.1.0.118\(c636e4r1p1t8\)
Huawei Leland-l22a
Huawei Leland-l22c Firmware<9.1.0.118\(c636e4r1p1t8\)
Huawei Leland-l22c
Apple watchOS<8.0.0.139\(c432\)
Apple macOS Mojave

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203