Executive brief
A critical vulnerability exists in U-Boot, a widely used bootloader for embedded devices and industrial hardware. An attacker could exploit this flaw to gain full control over a device during its startup process by sending malicious network traffic. This could lead to permanent device compromise, data theft, or complete operational shutdown of industrial equipment.
Technical details
A stack-based buffer overflow vulnerability exists in Das U-Boot through version 2019.07 within the nfs_mount_reply helper function of the nfs_handler. The flaw is triggered by insufficient validation of data lengths in incoming Network File System (NFS) mount replies. A remote, unauthenticated attacker on the same network can exploit this by sending a malicious NFS packet to a device attempting to boot over the network. Successful exploitation can lead to arbitrary code execution with the privileges of the bootloader, effectively compromising the entire system before the operating system even starts. Siemens has confirmed this affects Ruggedcom Rox II devices, and patches are available in version 2.17.1.
Affected products
- Das U-Boot U-Boot through 2019.07
- Siemens Corproation Ruggedcom Rox II family before V2.17.1
Timeline
- 2019-07-31: disclosed
- 2019-07-31: advisory: NVD published date
- 2026-05-12: advisory: Siemens published updated advisory for Ruggedcom products