Executive brief
A vulnerability exists in the U-Boot bootloader, which is widely used in embedded systems and industrial hardware like Siemens Ruggedcom devices. An attacker could exploit this flaw to gain full control over the device during its startup process. This could lead to complete system compromise, data theft, or permanent disruption of industrial operations.
Technical details
A stack-based buffer overflow (CWE-787) exists in Das U-Boot through version 2019.07. The vulnerability is located in the 'nfs_read_reply' function when calling 'store_block' during NFSv2 operations. It is caused by an unbounded 'memcpy' operation that lacks a proper length check on the incoming network packet. A remote attacker on the same network can exploit this by sending a malicious NFS reply to a device attempting to boot over the network, leading to arbitrary code execution with bootloader privileges. Siemens has confirmed this affects several Ruggedcom Rox II industrial devices, which have been patched in version 2.17.1.
Affected products
- Das U-Boot U-Boot through 2019.07
- Siemens Corproation Ruggedcom Rox II family before V2.17.1
Timeline
- 2019-07-31: disclosed
- 2019-07-31: advisory: NVD published CVE-2019-14194
- 2026-05-12: patched: Siemens released SSA-577017 for Ruggedcom Rox II devices