Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v664-mrh9-gw5q

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6

Описание

The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.

The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.

EPSS

Процентиль: 54%
0.00316
Низкий

6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6
nvd
больше 10 лет назад

The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.

EPSS

Процентиль: 54%
0.00316
Низкий

6 Medium

CVSS3