Impact
Dell Boot Optimized Server Storage (BOSS) versions before 2.2.13.2038 have an On-Chip Debug and Test Interface with Improper Access Control in the System Management Control Unit on the 17G BOSS-N1 controllers. An attacker who can physically reach the hardware could use this flaw to gain unauthorized access to the device’s internal management functions, potentially allowing manipulation of firmware or control of storage operations.
Affected Systems
The vulnerability affects Dell BOSS hardware running any firmware version earlier than 2.2.13.2038, with the 17G BOSS-N1 controller identified as the specific implementation in which the flaw resides.
Risk and Exploitability
The CVSS score of 5.1 denotes a moderate impact level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed large‑scale exploitation yet. The likely attack vector is a local physical attacker who can reach the server, making the risk contingent on the physical security posture of the environment. Effective mitigation reduces the risk to none.
OpenCVE Enrichment