CVE-2026-80359: Medium severity Dell Boot Optimized Server Storage (BOSS) vulnerability
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Boot Optimized Server Storage (BOSS)to a version that resolves this vulnerability.Fixed in 2.2.13.2038
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
The issue affects Dell 17G BOSS-N1 controllers running a BOSS version earlier than 2.2.13.2038. Exploitation requires physical access to the affected controller.
Does an attacker need credentials or user interaction?
No credentials or user interaction are required, but the attacker must have physical access. The vulnerability is in the SMCU's access control for an on-chip debug and test interface.
What is the remediation?
Update Dell Boot Optimized Server Storage (BOSS) to version 2.2.13.2038 or later. If updating cannot be performed immediately, restrict and monitor physical access to servers containing affected 17G BOSS-N1 controllers.