CVE-2015-2890: Dell BIOS

Medium severity, CVSS 6.0. EPSS: 1.1% chance of exploitation in the next 30 days.

The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.

Affected products

  • Dell BIOS: up to and including a20; up to and including a12; up to and including a15; up to and including a18; up to and including a14; version a13 only; …

Published 2015-08-01. Last modified 2026-06-17.