PatchSiren cyber security CVE debrief
CVE-2019-14198 Siemens CVE debrief
CVE-2019-14198 is a critical memory-corruption issue in Das U-Boot affecting versions through 2019.07. NVD describes an unbounded memcpy with a failed length check in nfs_read_reply when store_block is called in the NFSv3 case. Because the vulnerable path is network-facing and requires no privileges or user interaction, systems that boot over NFS or otherwise expose U-Boot network boot functionality should treat this as high priority.
- Vendor
- Siemens
- Product
- RUGGEDCOM ROX MX5000
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Embedded device vendors, firmware teams, and operators of systems that use U-Boot for network booting should care most. This is especially relevant for products that rely on NFSv3 boot flows or ship U-Boot-based firmware in exposed or field-deployed devices.
Technical summary
The NVD record classifies the weakness as CWE-787 and assigns CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The affected product criterion is denx:u-boot through 2019.07. The issue is described as an unbounded memcpy caused by a failed length check in nfs_read_reply during store_block handling in the NFSv3 case, which creates a memory-safety risk on attacker-influenced network input.
Defensive priority
Immediate. This is a critical, remotely reachable memory-corruption flaw in bootloader code and should be addressed as soon as practical in any environment that uses the affected U-Boot versions or NFS boot paths.
Recommended defensive actions
- Upgrade U-Boot to a version newer than 2019.07 that includes the fix for CVE-2019-14198.
- If NFS boot is not required, disable or remove the NFS boot path to reduce exposure.
- Inventory devices and firmware images to identify any use of affected U-Boot versions.
- Limit access to boot-time network services and isolate management or provisioning networks that may reach U-Boot NFS functionality.
- Follow vendor and project advisories for patch availability and deployment guidance.
Evidence notes
The debrief is grounded in the NVD CVE record and the official project/vendor references listed in the source corpus. NVD identifies the affected CPE as denx:u-boot through 2019.07, classifies the weakness as CWE-787, and assigns CVSS 3.0 9.8. The description specifically cites an unbounded memcpy with a failed length check in nfs_read_reply during the NFSv3 store_block path. No exploit details are included here.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-14198 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-14198
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-14198 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-14198
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.