Junglewise Threat Intelligence

CVE-2019-14201: Das U-Boot stack buffer overflow in nfs_lookup_reply

CVE-2019-14201 · Severity: critical · CVSS 9.8 · Published 2019-07-31

Technologies: Siemens ROX II, Das U-Boot U-Boot. Vendors: Siemens, Denx.

Executive brief

A critical vulnerability exists in U-Boot, a widely used bootloader for embedded devices and industrial hardware. The flaw occurs when the system processes network-based file system (NFS) responses, potentially allowing an attacker to take full control of the device during the boot process. This could lead to complete system compromise, data theft, or permanent disruption of industrial operations.

Technical details

A stack-based buffer overflow vulnerability exists in the Das U-Boot bootloader within the nfs_lookup_reply helper function of the nfs_handler. The root cause is an out-of-bounds write (CWE-787) when processing incoming NFS (Network File System) replies. An unauthenticated attacker on the same network can exploit this by sending a malicious NFS response to a device attempting to boot over the network. Successful exploitation can lead to arbitrary code execution with high privileges before the operating system has even started. The vulnerability is addressed in U-Boot versions following 2019.07 and in Siemens Ruggedcom Rox II versions 2.17.1 and later.

Affected products

  • Das U-Boot U-Boot through 2019.07
  • Siemens Ruggedcom Rox II family before 2.17.1

Timeline

  • 2019-07-31: disclosed: Initial NVD publication
  • 2026-05-12: advisory: Siemens published advisory SSA-577017 covering affected Ruggedcom products

References

Related threats