Dell · Precision Workstation · CVE-2015-2890
**Name of the Vulnerable Software and Affected Versions**
Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21
**Description**
The BIOS implementation does not enforce a BIOS CNTL locking protection mechanism upon being woken from sleep, allowing local users to conduct EFI flash attacks by leveraging console access.
**Recommendations**
For Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21, update the firmware to version A21 or later to resolve the issue.