Lucene search

K
cve[email protected]CVE-2015-2890
HistoryAug 01, 2015 - 1:59 a.m.

CVE-2015-2890

2015-08-0101:59:13
web.nvd.nist.gov
18
dell
bios
efi
flash attacks
cve-2015-2890

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.

Affected configurations

NVD
Node
dellbiosRangea20
AND
delllatitude_e6420_atg
OR
delllatitude_e6420_xfr
Node
dellbiosRangea12
AND
delllatitude_e6220
OR
delllatitude_xt3
Node
dellbiosRangea15
AND
delllatitude_e4310
OR
delllatitude_e5410
OR
delllatitude_e5510
OR
delllatitude_e6410_atg
OR
delllatitude_e6510
OR
dellprecision_mobile_m4600
OR
dellprecision_t1600
Node
dellbiosRangea18
AND
delllatitude_e6320
OR
delllatitude_e6520
Node
dellbiosRangea14
AND
dellprecision_mobile_m4500
OR
dellprecision_mobile_m6600
Node
dellbiosMatcha13
AND
delllatitude_e4310
OR
delllatitude_e5420
OR
delllatitude_e5520
Node
dellbiosRangea11
AND
dellprecision_t3600
OR
dellprecision_t5600
OR
dellprecision_t5600_xl
Node
dellbiosRangea10
AND
delloptiplex_390
Node
dellbiosRangea17
AND
delloptiplex_790
OR
delloptiplex_990
CPENameOperatorVersion
dell:biosdell bioslea20

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%