Junglewise Threat Intelligence

CVE-2019-14197: Das U-Boot out-of-bounds read in nfs_read_reply

CVE-2019-14197 · Severity: critical · CVSS 9.1 · Published 2019-07-31

Technologies: Siemens ROX II, Das U-Boot U-Boot. Vendors: Siemens, Denx.

Executive brief

A vulnerability was found in U-Boot, a widely used bootloader for embedded devices and industrial hardware. An attacker could exploit this flaw to read sensitive data from the device's memory or cause the system to crash during the network boot process. This could lead to information theft or a complete disruption of industrial operations and device availability.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Das U-Boot through version 2019.07 within the NFS (Network File System) implementation. The flaw is located in the 'nfs_read_reply' function, where insufficient validation of incoming network packets allows for reading data beyond the intended buffer. A remote, unauthenticated attacker on the same network can exploit this by sending malicious NFS replies during the boot process. This can result in a denial of service (system crash) or the exposure of sensitive memory contents. Siemens has also identified this vulnerability as affecting several Ruggedcom Rox II industrial devices, which use U-Boot in their firmware.

Affected products

  • Das U-Boot U-Boot through 2019.07
  • Siemens Ruggedcom Rox II family before 2.17.1

Timeline

  • 2019-07-31: disclosed: Initial CVE publication
  • 2026-05-12: advisory: Siemens published advisory SSA-577017 regarding Ruggedcom Rox II devices

References

Related threats