DSA-2026-402: Security Update for Dell Boot Optimized Server Storage (BOSS) Vulnerability

Summary: Dell Boot Optimized Server Storage (BOSS) remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Proprietary Code CVEs 

Description

CVSS Base Score

CVSS Vector String

CVE-2026-80357

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.

7.0

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2026-80359

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.

6.8

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

 

CVE-2026-80358

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.

5.1

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs 

Description

CVSS Base Score

CVSS Vector String

CVE-2026-80357

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.

7.0

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2026-80359

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.

6.8

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

 

CVE-2026-80358

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.

5.1

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

Dell Boot Optimized Server Storage (BOSS) N-1

Firmware

Versions prior to 2.2.13.2038

Version 2.2.13.2038

https://www.dell.com/support/home/drivers/driversdetails?driverid=GDT3C

 

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

Dell Boot Optimized Server Storage (BOSS) N-1

Firmware

Versions prior to 2.2.13.2038

Version 2.2.13.2038

https://www.dell.com/support/home/drivers/driversdetails?driverid=GDT3C

 

Workarounds & Mitigations

CVE ID

Workaround and Mitigation

CVE-2026-80357, CVE-2026-80358, CVE-2026-80359

  • Monitor the iDRAC Lifecycle Controller (LC) logs for intrusion events.
  • Customers who require additional assurance can enable UEFI Secure Boot in the BIOS settings and re-update to the latest BOSS firmware version number 2.2.13.2038.

 

Revision History

Revision

Date

Description

1.0

2026-09-24

Initial release

 

Related Information

Affected Products

Boot Optimized Server Storage (BOSS)
Article Properties
Article Number: 000513073
Article Type: Dell Security Advisory
Last Modified: 24 Sep 2026
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.