Sceawere

Vulnerability Detail

CVE-2026-80357UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell BOSS Improper Debug Access

Vulnerability Metadata

Severity
High
Score / CVSS
7
Creation Date
2h ago
Vendor
Dell
Product
Boot Optimized Server Storage (BOSS)
Attack Type
CWE-1191: On-Chip Debug and Test Interface With Improper Access Control
Vector String
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.0",
  "pubDate": "2026-09-28T15:17:23.717Z",
  "pubdate": "2026-09-28T15:17:23.717Z",
  "executiveSummary": "Dell Boot Optimized Server Storage (BOSS) controllers, specifically the 17G BOSS-N1 series, contain a vulnerability involving the On-Chip Debug and Test Interface within the System Management Control Unit (SMCU).\nThe vulnerability is categorized as an Improper Access Control issue, allowing unauthorized entities to bypass security restrictions imposed on the hardware's debugging subsystems.\nThe primary impact of this vulnerability is the potential for unauthorized access to the controller's internal state or firmware environment.\nExploitation is strictly contingent upon the attacker possessing physical access to the server hardware, which limits the attack surface but poses a significant risk in physical security-compromised environments.\nAffected products include Dell BOSS versions prior to 2.2.13.2038.\nGiven the nature of the interface, successful exploitation could facilitate advanced persistent threats, potential firmware manipulation, or the extraction of sensitive data managed by the storage controller, necessitating immediate remediation via firmware updates.",
  "technicalDetails": "The vulnerability resides within the SMCU (System Management Control Unit) of the 17G BOSS-N1 controllers utilized in Dell Boot Optimized Server Storage (BOSS) hardware.\nThe root cause is an Improper Access Control implementation within the On-Chip Debug and Test Interface, such as JTAG or similar hardware-level debug ports, which remain active or insufficiently protected in production firmware builds.\nBecause these interfaces are designed for low-level hardware debugging and maintenance, they inherently possess high-privilege access to the internal buses and memory space of the storage controller.\nExploitation requires physical access to the server chassis to interface directly with the hardware pins or dedicated debug headers on the BOSS-N1 controller board.\nAn unauthenticated attacker, upon gaining physical access, can utilize standard hardware debugging tools to attach to the exposed interface. By circumventing or failing to encounter the intended access controls, the attacker can halt the processor, read from or write to arbitrary memory locations, and inspect peripheral registers.\nThis unauthorized interaction bypasses traditional OS and firmware-level access control lists (ACLs) because it operates beneath the software stack. The attack flow involves physical connection, identification of the debug chain, and execution of hardware-level primitives to extract or manipulate internal firmware state.\nThe security implications are severe, as an attacker might leverage these capabilities to bypass secure boot verification, exfiltrate encryption keys if stored in volatile memory, or inject malicious code into the controller's firmware execution flow.\nThe vulnerability exists in all firmware versions prior to 2.2.13.2038. Once the debug interface is utilized to compromise the SMCU, the attacker effectively gains control over the storage controller's logic, leading to persistent unauthorized access to the storage subsystem managed by the BOSS-N1."
}
CVE-2026-80357: Dell BOSS Improper Debug Access (HIGH Severity, CVSS: 7.0) | Sceawere