CVE-2026-80357: High severity Dell Boot Optimized Server Storage (BOSS) vulnerability
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Boot Optimized Server Storage (BOSS)to a version that resolves this vulnerability.Fixed in 2.2.13.2038
Event History
Frequently Asked Questions
Which systems are affected?
The issue affects Dell 17G BOSS-N1 controllers running Dell Boot Optimized Server Storage (BOSS) versions earlier than 2.2.13.2038.
What access does an attacker need?
Exploitation requires physical access to the affected controller. The attacker does not need to authenticate, but user interaction is required according to the supplied severity vector.
Are systems running version 2.2.13.2038 affected?
The affected versions are stated as versions prior to 2.2.13.2038. Systems on 2.2.13.2038 are not included in the listed affected version range.