Access Control Flaw in Dell Boot Optimized Server Storage
CVE-2026-80357

7HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
28 September 2026

What is CVE-2026-80357?

An access control vulnerability exists in Dell Boot Optimized Server Storage (BOSS) in the SMCU of 17G BOSS-N1 controllers. This flaw allows unauthenticated attackers with physical access to exploit the system, potentially leading to unauthorized access to sensitive data and functionalities. Users are advised to update to version 2.2.13.2038 or later to mitigate this risk.

Affected Version(s)

Boot Optimized Server Storage (BOSS) 0 < 2.2.13.2038

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.