Junglewise Threat Intelligence

CVE-2019-14195: Das U-Boot stack overflow in nfs_readlink_reply

CVE-2019-14195 · Severity: critical · CVSS 9.8 · Published 2019-07-31

Technologies: Siemens ROX II, Das U-Boot U-Boot. Vendors: Siemens, Denx.

Executive brief

A critical vulnerability exists in U-Boot, a widely used bootloader for embedded devices and industrial hardware. An attacker could exploit this flaw over a network to execute unauthorized code or crash the system during the boot process. This could lead to complete device takeover, loss of operational control, or permanent disruption of industrial equipment.

Technical details

An out-of-bounds write (CWE-787) exists in Das U-Boot through version 2019.07 within the nfs_readlink_reply function. The vulnerability is caused by an unbounded memcpy operation where the length of a new path is not properly validated before being copied into a buffer. A remote attacker on the same network could provide a specially crafted NFS reply to trigger a buffer overflow. This can result in arbitrary code execution or a denial-of-service condition during the pre-boot environment. Siemens has identified this as affecting several RUGGEDCOM ROX II devices, which should be updated to V2.17.1 or later.

Affected products

  • Das U-Boot U-Boot through 2019.07
  • Siemens Corproation RUGGEDCOM ROX II family before V2.17.1

Timeline

  • 2019-07-31: disclosed
  • 2019-07-31: advisory: NVD published CVE-2019-14195
  • 2026-05-12: patched: Siemens released advisory SSA-577017 for Ruggedcom Rox products

References

Related threats