Description
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-09-28
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access through physical debug interface
Action: Patch Firmware
AI Analysis

Impact

Dell Boot Optimized Server Storage firmware prior to 2.2.13.2038 contains an improper access control flaw in the On‑Chip Debug and Test Interface on the SMCU in 17G BOSS‑N1 controllers. The flaw allows an attacker who can physically reach the device to use the debug interface without authentication, potentially enabling manipulation of the controller and its underlying storage system. The impact is determined by the ability to gain arbitrary control over the hardware through the interface.

Affected Systems

All Dell Boot Optimized Server Storage devices that run firmware versions earlier than 2.2.13.2038 on 17G BOSS‑N1 controllers are susceptible. These devices rely on the SMCU microcontroller subsystem for system management and storage control functions.

Risk and Exploitability

The CVSS score of 6.8 indicates a medium severity and the EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in CISA’s KEV catalog. Because the attack requires physical proximity to the hardware, the vector is local; remote exploitation is not described. An unauthenticated attacker with direct access to the controller could potentially exploit the debug interface to bypass authentication and gain control over the device.

Generated by OpenCVE AI on September 28, 2026 at 17:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell BOSS firmware to version 2.2.13.2038 or later
  • Implement strict physical access controls for BOSS‑N1 devices, ensuring only authorized personnel can access the hardware
  • If available, disable or lock the On‑Chip Debug and Test Interface to prevent unauthorized use

Generated by OpenCVE AI on September 28, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell boot Optimized Server Storage (boss)
Vendors & Products Dell
Dell boot Optimized Server Storage (boss)

Mon, 28 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-1191
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Boot Optimized Server Storage (boss)
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-28T15:33:31.451Z

Reserved: 2026-08-26T10:04:27.589Z

Link: CVE-2026-80359

cve-icon Vulnrichment

Updated: 2026-09-28T15:32:17.866Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-28T15:17:24.033

Modified: 2026-09-28T16:26:58.700

Link: CVE-2026-80359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:42:16Z

Weaknesses
  • CWE-1191

    On-Chip Debug and Test Interface With Improper Access Control