Impact
Dell Boot Optimized Server Storage firmware prior to 2.2.13.2038 contains an improper access control flaw in the On‑Chip Debug and Test Interface on the SMCU in 17G BOSS‑N1 controllers. The flaw allows an attacker who can physically reach the device to use the debug interface without authentication, potentially enabling manipulation of the controller and its underlying storage system. The impact is determined by the ability to gain arbitrary control over the hardware through the interface.
Affected Systems
All Dell Boot Optimized Server Storage devices that run firmware versions earlier than 2.2.13.2038 on 17G BOSS‑N1 controllers are susceptible. These devices rely on the SMCU microcontroller subsystem for system management and storage control functions.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity and the EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in CISA’s KEV catalog. Because the attack requires physical proximity to the hardware, the vector is local; remote exploitation is not described. An unauthenticated attacker with direct access to the controller could potentially exploit the debug interface to bypass authentication and gain control over the device.
OpenCVE Enrichment