Dell BOSS & Live Optics: Four Vulnerabilities Disclosed, Including Physical Access Flaw
Key findings • Dell disclosed four vulnerabilities on September 28, 2026, affecting BOSS and Live Optics Collector. • Three BOSS vulnerabilities stem from improper access control in the SMCU,…

Key findings
- Dell disclosed four vulnerabilities on September 28, 2026, affecting BOSS and Live Optics Collector.
- Three BOSS vulnerabilities stem from improper access control in the SMCU, with one rated High severity.
- A Use of Hard-coded Password vulnerability exists in Dell Live Optics Collector.
- Affected BOSS versions are prior to 2.2.13.2038; Live Optics Collector versions prior to 27.2.13.310.
- Patches are available as BOSS version 2.2.13.2038 and Live Optics Collector version 27.2.13.310.
On September 28, 2026, Dell disclosed four vulnerabilities affecting its server storage and data collection products. The batch includes three vulnerabilities in Dell Boot Optimized Server Storage (BOSS) and one in Dell Live Optics Collector. The BOSS vulnerabilities, all stemming from an On-Chip Debug and Test Interface With Improper Access Control flaw in the SMCU on 17G BOSS-N1 controllers, affect versions prior to 2.2.13.2038. The Live Optics Collector vulnerability, a Use of Hard-coded Password, impacts versions prior to 27.2.13.310.
The vulnerabilities in Dell BOSS, CVE-2026-80359, CVE-2026-80358, and CVE-2026-80357, share a common root cause: improper access control within the SMCU's debug and test interface. While all require physical access, their potential impact varies. CVE-2026-80357 is rated High with a CVSSv3 score of 7.0, while CVE-2026-80359 (Medium, 6.8) and CVE-2026-80358 (Medium, 5.1) also present risks. Successful exploitation could lead to unauthorized access or information exposure.
The fourth vulnerability, CVE-2026-70413, resides in Dell Live Optics Collector. This medium-severity flaw (CVSSv3 5.6) involves the use of a hard-coded password, which could be exploited by a low-privileged attacker with local access to expose sensitive information. This vulnerability affects versions prior to 27.2.13.310.
Dell has addressed the BOSS vulnerabilities by releasing version 2.2.13.2038. The Live Optics Collector vulnerability has been patched in version 27.2.13.310. Users of these Dell products are strongly advised to update to the latest versions to mitigate the risks associated with these vulnerabilities.
This batch of disclosures highlights the importance of maintaining up-to-date firmware and software for Dell's server and data management solutions. The physical access requirement for the BOSS vulnerabilities underscores the need for robust physical security measures in data center environments. Similarly, the hard-coded password in Live Optics serves as a reminder for developers to avoid embedding credentials directly into code. Users should consult Dell's official advisories for detailed remediation steps.