VYPR
Medium severity6.0NVD Advisory· Published Aug 1, 2015· Updated May 6, 2026

CVE-2015-2890

CVE-2015-2890

Description

The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.

Affected products

2
  • Dell/BIOS2 versions
    cpe:2.3:o:dell:bios:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:dell:bios:*:*:*:*:*:*:*:*range: <=a20
    • cpe:2.3:o:dell:bios:a13:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.