Improper Access Control Vulnerability in Dell Boot Optimized Server Storage
CVE-2026-80359

6.8MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
28 September 2026

What is CVE-2026-80359?

Dell Boot Optimized Server Storage (BOSS) versions prior to 2.2.13.2038 are subject to an improper access control vulnerability. This issue arises from the presence of an On-Chip Debug and Test Interface located within the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could exploit this vulnerability, potentially gaining unauthorized access to system resources, which poses significant risks to data integrity and confidentiality.

Affected Version(s)

Boot Optimized Server Storage (BOSS) 0 < 2.2.13.2038

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.