CVE-2015-2890

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/08/2015
Last modified:
12/04/2025

Description

The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:bios:*:*:*:*:*:*:*:* a20 (including)
cpe:2.3:h:dell:latitude_e6420_atg:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e6420_xfr:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:bios:*:*:*:*:*:*:*:* a12 (including)
cpe:2.3:h:dell:latitude_e6220:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_xt3:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:bios:*:*:*:*:*:*:*:* a15 (including)
cpe:2.3:h:dell:latitude_e4310:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e5410:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e5510:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e6410_atg:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e6510:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_mobile_m4600:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_t1600:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:bios:*:*:*:*:*:*:*:* a18 (including)