CVE-2015-2890
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
Published:Aug 1, 2015
Last Modified:Apr 12, 2025
EPS:Aug 1, 2015
EPSS Score:0.00429
CVSS Score:6
Affected Products
Vendor
Product
Action
Vendor
Dell
Product
Bios
Dell
Bios
Vendor
Dell
Product
Latitude E4310
Dell
Latitude E4310
Vendor
Dell
Product
Latitude E5410
Dell
Latitude E5410
Vendor
Dell
Product
Latitude E5420
Dell
Latitude E5420
Vendor
Dell
Product
Latitude E5510
Dell
Latitude E5510
Vendor
Dell
Product
Latitude E5520
Dell
Latitude E5520
Vendor
Dell
Product
Latitude E6220
Dell
Latitude E6220
Vendor
Dell
Product
Latitude E6320
Dell
Latitude E6320
Vendor
Dell
Product
Latitude E6410 Atg
Dell
Latitude E6410 Atg
Vendor
Dell
Product
Latitude E6420 Atg
Dell
Latitude E6420 Atg
Vendor
Dell
Product
Latitude E6420 Xfr
Dell
Latitude E6420 Xfr
Vendor
Dell
Product
Latitude E6510
Dell
Latitude E6510
Vendor
Dell
Product
Latitude E6520
Dell
Latitude E6520
Vendor
Dell
Product
Latitude Xt3
Dell
Latitude Xt3
Vendor
Dell
Product
Optiplex 390
Dell
Optiplex 390
Vendor
Dell
Product
Optiplex 790
Dell
Optiplex 790
Vendor
Dell
Product
Optiplex 990
Dell
Optiplex 990
Vendor
Dell
Product
Precision Mobile M4500
Dell
Precision Mobile M4500
Vendor
Dell
Product
Precision Mobile M4600
Dell
Precision Mobile M4600
Vendor
Dell
Product
Precision Mobile M6600
Dell
Precision Mobile M6600
Vendor
Dell
Product
Precision T1600
Dell
Precision T1600
Vendor
Dell
Product
Precision T3600
Dell
Precision T3600
Vendor
Dell
Product
Precision T5600
Dell
Precision T5600
Vendor
Dell
Product
Precision T5600 Xl
Dell
Precision T5600 Xl
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
