Vulnerability Details CVE-2015-2890
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.6%
CVSS Severity
CVSS v3 Score 6.0
CVSS v2 Score 7.2
Products affected by CVE-2015-2890
-
cpe:2.3:h:dell:latitude_e4310:-
-
cpe:2.3:h:dell:latitude_e5410:-
-
cpe:2.3:h:dell:latitude_e5420:-
-
cpe:2.3:h:dell:latitude_e5510:-
-
cpe:2.3:h:dell:latitude_e5520:-
-
cpe:2.3:h:dell:latitude_e6220:-
-
cpe:2.3:h:dell:latitude_e6320:-
-
cpe:2.3:h:dell:latitude_e6410_atg:-
-
cpe:2.3:h:dell:latitude_e6420_atg:-
-
cpe:2.3:h:dell:latitude_e6420_xfr:-
-
cpe:2.3:h:dell:latitude_e6510:-
-
cpe:2.3:h:dell:latitude_e6520:-
-
cpe:2.3:h:dell:latitude_xt3:-
-
cpe:2.3:h:dell:optiplex_390:-
-
cpe:2.3:h:dell:optiplex_790:-
-
cpe:2.3:h:dell:optiplex_990:-
-
cpe:2.3:h:dell:precision_mobile_m4500:-
-
cpe:2.3:h:dell:precision_mobile_m4600:-
-
cpe:2.3:h:dell:precision_mobile_m6600:-
-
cpe:2.3:h:dell:precision_t1600:-
-
cpe:2.3:h:dell:precision_t3600:-
-
cpe:2.3:h:dell:precision_t5600:-
-
cpe:2.3:h:dell:precision_t5600_xl:-
-
-
cpe:2.3:o:dell:bios:2.21.0
-
cpe:2.3:o:dell:bios:2.25.0
-
-
-
-
-
-
-
-
-