important · Firmware — Physical
Dell BOSS-N1 firmware can persist while iDRAC verifies a clean inactive image.
Affects
Dell 17G Boot Optimized Server Storage N-1 controllers used as operating-system boot storage in PowerEdge and related servers.
Physical bus access, or equivalent access after an iDRAC compromise, reaches unauthenticated S-MCU debugging and update paths. Modified firmware can then redirect verification reads to the unchanged slot.
Detail and 3 sources
Dell published remediation, but pre-fix firmware images remain acceptable.
Sources
ResearchDSA-2026-402: Security Update for Dell Boot Optimized Server Storage (BOSS) Vulnerability | Dell NamibiaResearchBOSS-N1 DC-MHS Firmware | Driver Details | Dell NamibiaCode / PoCDell BOSS-N1 S-MCU Firmware Integrity and Cryptographic Verification Bypass · Advisory · google/security-research · GitHub