CVE Feed

    Dashboard / CVE / CVE-2015-2890

    CVE-2015-2890

    The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.

    Published:Aug 1, 2015
    Last Modified:Apr 12, 2025
    EPS:Aug 1, 2015
    EPSS Score:0.00429
    CVSS Score:6

    Affected Products

    Vendor
    Dell
    Product
    Bios
    Vendor
    Dell
    Product
    Latitude E4310
    Vendor
    Dell
    Product
    Latitude E5410
    Vendor
    Dell
    Product
    Latitude E5420
    Vendor
    Dell
    Product
    Latitude E5510
    Vendor
    Dell
    Product
    Latitude E5520
    Vendor
    Dell
    Product
    Latitude E6220
    Vendor
    Dell
    Product
    Latitude E6320
    Vendor
    Dell
    Product
    Latitude E6410 Atg
    Vendor
    Dell
    Product
    Latitude E6420 Atg
    Vendor
    Dell
    Product
    Latitude E6420 Xfr
    Vendor
    Dell
    Product
    Latitude E6510
    Vendor
    Dell
    Product
    Latitude E6520
    Vendor
    Dell
    Product
    Latitude Xt3
    Vendor
    Dell
    Product
    Optiplex 390
    Vendor
    Dell
    Product
    Optiplex 790
    Vendor
    Dell
    Product
    Optiplex 990
    Vendor
    Dell
    Product
    Precision Mobile M4500
    Vendor
    Dell
    Product
    Precision Mobile M4600
    Vendor
    Dell
    Product
    Precision Mobile M6600
    Vendor
    Dell
    Product
    Precision T1600
    Vendor
    Dell
    Product
    Precision T3600
    Vendor
    Dell
    Product
    Precision T5600
    Vendor
    Dell
    Product
    Precision T5600 Xl

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High