PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-14193 Siemens CVE debrief

CVE-2019-14193 is a critical memory-corruption vulnerability in Das U-Boot through 2019.07. NVD describes an unbounded memcpy with an unvalidated length in nfs_readlink_reply after calculating a new path length, and rates the issue 9.8 (CVSS 3.0: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vendor
Siemens
Product
RUGGEDCOM ROX MX5000
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Teams maintaining or deploying U-Boot/DENX U-Boot should treat this as high priority, especially if the firmware uses U-Boot NFS functionality or receives network-controlled NFS data.

Technical summary

The vulnerable code path is nfs_readlink_reply. According to the CVE description, the function calculates a new path length and then enters an if block that performs memcpy using an unvalidated length. That pattern maps to CWE-787 (out-of-bounds write / memory corruption) and can lead to severe confidentiality, integrity, and availability impact under the NVD-assigned CVSS vector.

Defensive priority

Critical. The NVD record assigns a 9.8 score and a network-reachable, no-authentication, no-user-interaction vector. Prioritize inventorying U-Boot instances, confirming whether versions at or below 2019.07 are present, and applying vendor guidance or updates before relying on the affected NFS path handling.

Recommended defensive actions

  • Inventory devices and firmware images that include U-Boot and identify any versions through 2019.07.
  • Apply the vendor or upstream fix guidance referenced in the advisory and repository links once a patched release is confirmed.
  • If NFS-based functionality is not required in a given deployment, disable or restrict it as part of the mitigation plan.
  • Treat systems that process untrusted network input during boot as urgent patch candidates and validate them in staging before field rollout.
  • Coordinate firmware update and rollback plans for embedded devices where replacing U-Boot requires controlled maintenance windows.

Evidence notes

This debrief is based only on the supplied CVE record and its referenced links. The NVD metadata states: affected versions through 2019.07, CWE-787, and CVSS 3.0 9.8 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The description specifically cites an unbounded memcpy with an unvalidated length in nfs_readlink_reply after calculating the new path length. The CVE was published on 2019-07-31; the later 2026-05-12 modification date is metadata update context, not the disclosure date.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-14193 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-14193

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-14193 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-14193

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.