Junglewise Threat Intelligence

CVE-2019-14192: Das U-Boot integer underflow in UDP packet parsing

CVE-2019-14192 · Severity: critical · CVSS 9.8 · Published 2019-07-31

Technologies: Siemens ROX II, Das U-Boot U-Boot. Vendors: Siemens, Denx.

Executive brief

A vulnerability was found in the U-Boot bootloader, which is widely used in embedded systems and networking hardware to start the operating system. An attacker could send specially crafted network traffic to take full control of the device before the main security protections of the operating system even begin to run. This could lead to permanent device compromise, data theft, or complete service disruption.

Technical details

An integer underflow vulnerability exists in Das U-Boot through version 2019.07 within the net_process_received_packet function. The flaw is triggered during an nc_input_packet call when parsing incoming UDP packets, leading to an unbounded memcpy operation. A remote, unauthenticated attacker can exploit this by sending malicious UDP packets to a device running the vulnerable bootloader. This results in an out-of-bounds write (stack or heap-based buffer overflow), potentially allowing for remote code execution (RCE) in the pre-boot environment. Siemens has also identified this vulnerability as affecting several Ruggedcom Rox II industrial networking products, which have been patched in version 2.17.1.

Affected products

  • Das U-Boot U-Boot through 2019.07
  • Siemens Ruggedcom Rox II family before 2.17.1

Timeline

  • 2019-07-31: disclosed
  • 2019-07-31: advisory
  • 2026-05-12: other: Siemens published a downstream advisory for Ruggedcom products.

References

Related threats