Dell BOSS 17G N1: OTDI Improper Access Control (before 2.2.13.2038)
CVE-2026-80359 Published on September 28, 2026
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
Vulnerability Analysis
CVE-2026-80359 can be exploited with physical access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Exposed Chip Debug and Test Interface With Insufficient or Missing Authorization
The chip does not implement or does not correctly check whether users are authorized to access internal registers.
Affected Versions
Dell Boot Optimized Server Storage (BOSS):- Before 2.2.13.2038 is affected.