Executive brief
A critical vulnerability exists in the U-Boot bootloader, which is widely used in embedded systems and networking hardware. An attacker could exploit this flaw to gain full control over a device during its startup process. This could lead to permanent device compromise, data theft, or a complete loss of service for the affected hardware.
Technical details
A stack-based buffer overflow vulnerability exists in Das U-Boot through version 2019.07 within the nfs_handler reply helper function 'rpc_lookup_reply'. The flaw is caused by improper bounds checking when processing RPC lookup replies over the network via NFS. A remote, unauthenticated attacker can exploit this by sending specially crafted packets to a device running the vulnerable bootloader. Successful exploitation can lead to arbitrary code execution with high privileges, potentially allowing for a full system compromise before the operating system even loads. Siemens has identified this as affecting several Ruggedcom Rox II devices, with fixes available in version 2.17.1.
Affected products
- Das U-Boot U-Boot through 2019.07
- Siemens Ruggedcom Rox II family before 2.17.1
Timeline
- 2019-07-31: disclosed
- 2019-07-31: advisory: NVD published date
- 2026-05-12: patched: Siemens released Ruggedcom Rox II V2.17.1