BIOS Flash Attack Vulnerability on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions Devices

BIOS Flash Attack Vulnerability on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions Devices

CVE-2015-2890 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.

Learn more about our Cis Benchmark Audit For Apple Ios.