DSA-2026-402: Security Update for Dell Boot Optimized Server Storage (BOSS) Vulnerability
Summary: Dell Boot Optimized Server Storage (BOSS) remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-80357 |
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access. |
7.0 |
|
|
CVE-2026-80359 |
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access. |
6.8 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
|
CVE-2026-80358 |
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access. |
5.1 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-80357 |
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access. |
7.0 |
|
|
CVE-2026-80359 |
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access. |
6.8 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
|
CVE-2026-80358 |
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access. |
5.1 |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
Dell Boot Optimized Server Storage (BOSS) N-1 |
Firmware |
Versions prior to 2.2.13.2038 |
Version 2.2.13.2038 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=GDT3C |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
Dell Boot Optimized Server Storage (BOSS) N-1 |
Firmware |
Versions prior to 2.2.13.2038 |
Version 2.2.13.2038 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=GDT3C |
Workarounds & Mitigations
|
CVE ID |
Workaround and Mitigation |
|
CVE-2026-80357, CVE-2026-80358, CVE-2026-80359 |
|
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2026-09-24 |
Initial release |