Junglewise Threat Intelligence

CVE-2019-14200: Das U-Boot stack overflow in rpc_lookup_reply

CVE-2019-14200 · Severity: critical · CVSS 9.8 · Published 2019-07-31

Technologies: Siemens ROX II, Das U-Boot U-Boot. Vendors: Siemens, Denx.

Executive brief

A critical vulnerability exists in the U-Boot bootloader, which is widely used in embedded systems and networking hardware. An attacker could exploit this flaw to gain full control over a device during its startup process. This could lead to permanent device compromise, data theft, or a complete loss of service for the affected hardware.

Technical details

A stack-based buffer overflow vulnerability exists in Das U-Boot through version 2019.07 within the nfs_handler reply helper function 'rpc_lookup_reply'. The flaw is caused by improper bounds checking when processing RPC lookup replies over the network via NFS. A remote, unauthenticated attacker can exploit this by sending specially crafted packets to a device running the vulnerable bootloader. Successful exploitation can lead to arbitrary code execution with high privileges, potentially allowing for a full system compromise before the operating system even loads. Siemens has identified this as affecting several Ruggedcom Rox II devices, with fixes available in version 2.17.1.

Affected products

  • Das U-Boot U-Boot through 2019.07
  • Siemens Ruggedcom Rox II family before 2.17.1

Timeline

  • 2019-07-31: disclosed
  • 2019-07-31: advisory: NVD published date
  • 2026-05-12: patched: Siemens released Ruggedcom Rox II V2.17.1

References

Related threats