Description
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-09-28
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access through improper access control on physical hardware
Action: Assess Impact
AI Analysis

Impact

Dell Boot Optimized Server Storage (BOSS) versions before 2.2.13.2038 have an On-Chip Debug and Test Interface with Improper Access Control in the System Management Control Unit on the 17G BOSS-N1 controllers. An attacker who can physically reach the hardware could use this flaw to gain unauthorized access to the device’s internal management functions, potentially allowing manipulation of firmware or control of storage operations.

Affected Systems

The vulnerability affects Dell BOSS hardware running any firmware version earlier than 2.2.13.2038, with the 17G BOSS-N1 controller identified as the specific implementation in which the flaw resides.

Risk and Exploitability

The CVSS score of 5.1 denotes a moderate impact level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed large‑scale exploitation yet. The likely attack vector is a local physical attacker who can reach the server, making the risk contingent on the physical security posture of the environment. Effective mitigation reduces the risk to none.

Generated by OpenCVE AI on September 28, 2026 at 15:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s recommended security update that upgrades BOSS firmware to version 2.2.13.2038 or later, as documented in the Dell DSA-2026-402 advisory.
  • Ensure strict physical security controls around server locations, limiting access to authorized personnel only and monitoring for unauthorized movement.
  • Disable or lock the On‑Chip Debug and Test Interface on affected BOSS-N1 controllers, or otherwise enforce proper access controls to prevent exploitation of the signal path.

Generated by OpenCVE AI on September 28, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell boot Optimized Server Storage (boss)
Vendors & Products Dell
Dell boot Optimized Server Storage (boss)

Mon, 28 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Physical Access Unauthorized Exploit via Improper Access Control on Dell BOSS SMCU

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-1191
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L'}


Subscriptions

Dell Boot Optimized Server Storage (boss)
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-28T16:22:26.301Z

Reserved: 2026-08-26T10:04:27.589Z

Link: CVE-2026-80358

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-28T15:17:23.887

Modified: 2026-09-28T16:26:58.700

Link: CVE-2026-80358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:22:05Z

Weaknesses
  • CWE-1191

    On-Chip Debug and Test Interface With Improper Access Control