Description
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
Published: 2015-08-01
Score: 6.0 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2015-2978 The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
History

No history.

Subscriptions

Dell Bios Latitude E4310 Latitude E5410 Latitude E5420 Latitude E5510 Latitude E5520 Latitude E6220 Latitude E6320 Latitude E6410 Atg Latitude E6420 Atg Latitude E6420 Xfr Latitude E6510 Latitude E6520 Latitude Xt3 Optiplex 390 Optiplex 790 Optiplex 990 Precision Mobile M4500 Precision Mobile M4600 Precision Mobile M6600 Precision T1600 Precision T3600 Precision T5600 Precision T5600 Xl
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-06T05:32:20.350Z

Reserved: 2015-04-03T00:00:00.000Z

Link: CVE-2015-2890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-08-01T01:59:13.943

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-2890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses