7.2

CVE-2015-2890

The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Bios Version <= a20
Dell ≫ Bios Version <= a12
   Dell ≫ Latitude E6220
   Dell ≫ Latitude Xt3
Dell ≫ Bios Version <= a15
Dell ≫ Bios Version <= a18
   Dell ≫ Latitude E6320
   Dell ≫ Latitude E6520
Dell ≫ Bios Version <= a14
Dell ≫ Bios Version a13
   Dell ≫ Latitude E4310
   Dell ≫ Latitude E5420
   Dell ≫ Latitude E5520
Dell ≫ Bios Version <= a11
Dell ≫ Bios Version <= a10
   Dell ≫ Optiplex 390
Dell ≫ Bios Version <= a17
   Dell ≫ Optiplex 790
   Dell ≫ Optiplex 990
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.77% 0.506
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6 0.8 5.2
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.kb.cert.org/vuls/id/577140
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/BLUU-9XXQ9L
Third Party Advisory
US Government Resource