CVE-2015-2890
Last modified
CVE-2015-2890 is a medium-severity vulnerability rated 6/10 on the CVSS scale. The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Bios | <= a20 |
| Dell | Bios | <= a12 |
| Dell | Bios | <= a15 |
| Dell | Bios | <= a18 |
| Dell | Bios | <= a14 |
| Dell | Bios | a13 |
| Dell | Bios | <= a11 |
| Dell | Bios | <= a10 |
| Dell | Bios | <= a17 |
References
- http://www.kb.cert.org/vuls/id/577140Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/BLUU-9XXQ9LThird Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/577140Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/BLUU-9XXQ9LThird Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-2890?
How severe is CVE-2015-2890?
How do I fix CVE-2015-2890?
Are you affected by CVE-2015-2890?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
