Improper Access Control in Dell Boot Optimized Server Storage
CVE-2026-80358

5.1MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
28 September 2026

What is CVE-2026-80358?

Dell Boot Optimized Server Storage (BOSS) prior to version 2.2.13.2038 exposes an On-Chip Debug and Test Interface vulnerability in its SMCU on 17G BOSS-N1 controllers. An attacker with physical access could exploit this flaw to gain unauthorized access, potentially compromising system integrity and security.

Affected Version(s)

Boot Optimized Server Storage (BOSS) 0 < 2.2.13.2038

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.