CVE-2026-80358: Medium severity Dell Boot Optimized Server Storage (BOSS) vulnerability
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Boot Optimized Server Storage (BOSS)to a version that resolves this vulnerability.Fixed in 2.2.13.2038
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
The issue affects 17G BOSS-N1 controllers running Dell Boot Optimized Server Storage (BOSS) versions earlier than 2.2.13.2038.
What access does an attacker need?
An attacker must have physical access to the affected controller. The vulnerability does not require authentication, but exploitation also requires user interaction and has high attack complexity.
What is the impact of successful exploitation?
Successful exploitation could result in unauthorized access. The reported impact includes low confidentiality impact, high integrity impact, and low availability impact.