PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-19244 Rockwell Automation CVE debrief

A vulnerability exists in SQLite 3.30.1 that can cause a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage. This issue is rated as HIGH severity with a CVSS score of 7.5. The vulnerability affects systems using SQLite 3.30.1, particularly those where user input is used to construct SQL queries. Defenders and developers should assess exposure and prioritize patching to prevent potential system crashes or anomalies. The vulnerability has been publicly disclosed and patches are available.

Vendor
Rockwell Automation
Product
DataMosaix Private Cloud
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2019-11-25
Original CVE updated
2026-10-08
Advisory published
2019-11-25
Advisory updated
2026-10-08

Who should care

Defenders and developers using SQLite 3.30.1, especially in systems where user input is used to construct SQL queries, should assess exposure and prioritize patching to prevent potential system crashes or anomalies. This includes reviewing and restricting user input to SQL queries, monitoring systems for potential crashes or anomalies, and verifying and applying patches for SQLite 3.30.1. Additionally, security teams and vulnerability management teams may

Why it matters

This vulnerability can cause a crash in SQLite 3.30.1, which can impact system availability and requires verification and patching.

  • Potential system crashes or anomalies
  • Need for verification and patching of SQLite 3.30.1
  • Importance of restricting user input to SQL queries

Technical summary

The sqlite3Select function in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage. This vulnerability can impact system availability and requires verification and patching of SQLite 3.30.1, especially in systems where user input is used to construct SQL queries. The vulnerability has a CVSS score of 7.5, indicating high severity. Defenders should prioritize verifying and applying patches for SQLite 3.30.1 to prevent potential system crashes or anomalies.

Defensive priority

Defenders should prioritize verifying and applying patches for SQLite 3.30.1, especially in systems where user input is used to construct SQL queries.

Recommended defensive actions

  • Verify and apply patches for SQLite 3.30.1
  • Review and restrict user input to SQL queries
  • Monitor systems for potential crashes or anomalies
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its description and CVSS score. Additional references include a Siemens security advisory and a patch commit from the SQLite repository.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-19244 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-19244

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-19244 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-19244

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.