Executive brief
A vulnerability was found in the U-Boot bootloader, which is widely used in embedded systems and networking hardware to start the operating system. An attacker could send specially crafted network traffic to take full control of the device before the main security protections of the operating system even begin to run. This could lead to complete device compromise, data theft, or permanent disruption of the hardware.
Technical details
An integer underflow vulnerability exists in Das U-Boot through version 2019.07 within the net_process_received_packet function. When the software processes a specially crafted UDP packet, the underflow occurs during a call to the udp_packet_handler, leading to an unbounded memcpy operation. This is a classic buffer overflow scenario that can be triggered remotely over the network without authentication. A successful exploit allows an attacker to execute arbitrary code with high privileges during the boot process. Siemens has also identified this as affecting various Ruggedcom Rox II devices, recommending an update to version 2.17.1 or later.
Affected products
- Das U-Boot U-Boot through 2019.07
- Siemens Ruggedcom Rox II family before 2.17.1
Timeline
- 2019-07-31: disclosed
- 2019-07-31: advisory: NVD published CVE-2019-14199
- 2026-05-12: advisory: Siemens released SSA-577017 addressing the issue in Ruggedcom products