{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T13:06:29.437","vulnerabilities":[{"cve":{"id":"CVE-2019-5220","sourceIdentifier":"psirt@huawei.com","published":"2019-07-10T18:15:11.067","lastModified":"2026-06-17T02:37:19.490","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Successful exploit could allow the attacker bypass the FRP protection. Affected products: Mate 20 X, versions earlier than Ever-AL00B 9.0.0.200(C00E200R2P1); Mate 20, versions earlier than Hima-AL00B/Hima-TL00B 9.0.0.200(C00E200R2P1); Honor Magic 2, versions earlier than Tony-AL00B/Tony-TL00B 9.0.0.182(C00E180R2P2)."},{"lang":"es","value":"Hay una vulnerabilidad de omisión de la protección Factory Reset Protection (FRP) en varios teléfonos inteligentes. El sistema no comprueba de manera suficiente el permiso, un atacante podría realizar una determinada operación en cierto paso del asistente de configuración. La explotación con éxito podría permitir al atacante omitir la protección FRP. Productos afectados: Mate 20 X, versiones anteriores a Ever-AL00B 9.0.0.200(C00E200R2P1); Mate 20, versiones anteriores a Hima-AL00B/Hima-TL00B 9.0.0.200(C00E200R2P1); Honor Magic 2, versiones anteriores a Tony-AL00B/Tony-TL00B 9.0.0.182(C00E180R2P2)"}],"affected":[{"source":"psirt@huawei.com","affectedData":[{"vendor":"Huawei","product":"Mate 20 X","versions":[{"version":"Versions earlier than Ever-AL00B 9.0.0.200(C00E200R2P1)","status":"affected"}]},{"vendor":"Huawei","product":"Mate 20","versions":[{"version":"Versions earlier than Hima-AL00B/Hima-TL00B 9.0.0.200(C00E200R2P1)","status":"affected"}]},{"vendor":"Huawei","product":"Honor Magic 2","versions":[{"version":"Versions earlier than Tony-AL00B/Tony-TL00B 9.0.0.182(C00E180R2P2)","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:mate_20_x_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"ever-al00b_9.0.0.200\\(c00e200r2p1\\)","matchCriteriaId":"6E9B173D-4E18-4147-8900-9F236A01F701"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:huawei:mate_20_x:-:*:*:*:*:*:*:*","matchCriteriaId":"5FD3779B-F943-4B7E-BF82-AA4A051D02C8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"hima-al00b\\/hima-tl00b_9.0.0.200\\(c00e200r2p1\\)","matchCriteriaId":"014B53F4-1EF7-4C2C-BED1-B0D1ECC7BFC7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:*","matchCriteriaId":"B5322963-9375-4E4E-8119-895C224003AE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:honor_magic_2_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"tony-al00b\\/tony-tl00b_9.0.0.182\\(c00e180r2p2\\)","matchCriteriaId":"9385366D-823E-48E6-9A90-63E90D93C178"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:huawei:honor_magic_2:-:*:*:*:*:*:*:*","matchCriteriaId":"3F3A0DA8-F39F-4343-856C-4BCDFB874DD2"}]}]}],"references":[{"url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190626-01-frp-en","source":"psirt@huawei.com","tags":["Vendor Advisory"]},{"url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190626-01-frp-en","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}