Junglewise Threat Intelligence

CVE-2019-14198: Das U-Boot unbounded memcpy in nfs_read_reply

CVE-2019-14198 · Severity: critical · CVSS 9.8 · Published 2019-07-31

Technologies: Siemens ROX II, Das U-Boot U-Boot. Vendors: Siemens, Denx.

Executive brief

A vulnerability was found in U-Boot, a widely used bootloader for embedded devices and industrial hardware. An attacker could exploit this flaw to execute unauthorized code or crash the system during the network booting process. This could lead to a complete takeover of the device or a permanent disruption of operations.

Technical details

An out-of-bounds write (CWE-787) exists in Das U-Boot through version 2019.07. The vulnerability is caused by an unbounded memcpy operation within the 'nfs_read_reply' function when calling 'store_block' during NFSv3 operations. Specifically, a failed or missing length check on data received from a network-reachable NFS server allows for a buffer overflow. An attacker controlled NFS server could provide a malicious response to trigger this overflow, potentially leading to remote code execution (RCE) before the operating system has even loaded. Siemens has also identified this as affecting various Ruggedcom Rox II industrial devices that utilize the vulnerable U-Boot code.

Affected products

  • Das U-Boot U-Boot through 2019.07
  • Siemens Ruggedcom Rox II family before V2.17.1

Timeline

  • 2019-07-31: disclosed
  • 2019-07-31: advisory: NVD Published Date
  • 2026-05-12: patched: Siemens released Ruggedcom Rox V2.17.1 to address the issue in their products.

References

Related threats