The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.

Project Subscriptions

Vendors Products
Latitude E4310 Subscribe
Latitude E5410 Subscribe
Latitude E5420 Subscribe
Latitude E5510 Subscribe
Latitude E5520 Subscribe
Latitude E6220 Subscribe
Latitude E6320 Subscribe
Latitude E6410 Atg Subscribe
Latitude E6420 Atg Subscribe
Latitude E6420 Xfr Subscribe
Latitude E6510 Subscribe
Latitude E6520 Subscribe
Latitude Xt3 Subscribe
Optiplex 390 Subscribe
Optiplex 790 Subscribe
Optiplex 990 Subscribe
Precision Mobile M4500 Subscribe
Precision Mobile M4600 Subscribe
Precision Mobile M6600 Subscribe
Precision T1600 Subscribe
Precision T3600 Subscribe
Precision T5600 Subscribe
Precision T5600 Xl Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2015-2978 The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-06T05:32:20.350Z

Reserved: 2015-04-03T00:00:00.000Z

Link: CVE-2015-2890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-08-01T01:59:13.943

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-2890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses