Impact
Dell Boot Optimized Server Storage (BOSS) versions prior to firmware 2.2.13.2038 contain an On‑Chip Debug and Test Interface that suffers from improper access control in the System Management Controller Unit (SMCU) on 17G BOSS‑N1 controllers. An attacker with physical access can use this vulnerable interface to gain unauthorized access to the storage subsystem, potentially compromising the confidentiality and integrity of data and allowing covert control over the firmware.
Affected Systems
Systems that employ Dell BOSS components, specifically the 17G BOSS‑N1 controller, and run firmware versions earlier than 2.2.13.2038 are affected. This vulnerability is limited to Dell BOSS hardware and does not impact other Dell or third‑party storage solutions.
Risk and Exploitability
The CVSS score of 7 indicates high severity. Because the flaw requires direct physical access to the debug interface, the likelihood of exploitation in the wild is low until an attacker gains such access. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation. Once an attacker has physical proximity, the vulnerability could be used to take full control of the storage stack. The likely attack vector is an attacker physically accessing the On‑Chip Debug and Test Interface.
OpenCVE Enrichment