PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-14195 Siemens CVE debrief

CVE-2019-14195 is a critical memory corruption issue in Das U-Boot affecting versions through 2019.07. The flaw is in NFS readlink handling, where an unbounded memcpy uses an unvalidated length in nfs_readlink_reply after the new path length is computed. Because the issue is reachable in networking code and scored 9.8, it should be treated as urgent for any environment that boots or interacts with U-Boot over NFS.

Vendor
Siemens
Product
RUGGEDCOM ROX MX5000
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Embedded platform teams, bootloader maintainers, OEMs, and operators who use U-Boot in network-boot or NFS-based startup paths. Security teams responsible for firmware, device lifecycle management, and supply-chain validation should also prioritize review.

Technical summary

NVD describes the issue as an unbounded memcpy with an unvalidated length in nfs_readlink_reply, specifically in the else block after calculating the new path length. The affected product set is U-Boot through 2019.07, and NVD assigns CWE-787. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting a remotely reachable flaw with high impact.

Defensive priority

High. This is a pre-boot/bootloader vulnerability with remote attack surface in NFS-related functionality and a critical CVSS score. Systems that use U-Boot for network booting or unattended device provisioning should be reviewed first.

Recommended defensive actions

  • Verify whether any deployed U-Boot builds are at or below 2019.07.
  • Prioritize upgrading to a fixed U-Boot release or vendor-maintained build that explicitly addresses CVE-2019-14195.
  • If immediate upgrade is not possible, disable or restrict NFS-based boot paths and any affected readlink-related network boot behavior.
  • Rebuild and redeploy firmware images from trusted sources after patching, then confirm the active bootloader version on target devices.
  • Use vendor advisories and official release notes to confirm whether downstream firmware packages include the fix.
  • Add firmware inventory and SBOM checks so U-Boot versions are tracked across device fleets.

Evidence notes

The vulnerability description, affected version boundary, CVSS, and CWE come from the supplied NVD record. The CVE record and NVD detail pages are official references. The source corpus also lists a third-party advisory and the upstream U-Boot repository as references, but no additional technical claims beyond the NVD description are used here.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-14195 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-14195

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-14195 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-14195

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.