PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-14198 Siemens CVE debrief

CVE-2019-14198 is a critical memory-corruption issue in Das U-Boot affecting versions through 2019.07. NVD describes an unbounded memcpy with a failed length check in nfs_read_reply when store_block is called in the NFSv3 case. Because the vulnerable path is network-facing and requires no privileges or user interaction, systems that boot over NFS or otherwise expose U-Boot network boot functionality should treat this as high priority.

Vendor
Siemens
Product
RUGGEDCOM ROX MX5000
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Embedded device vendors, firmware teams, and operators of systems that use U-Boot for network booting should care most. This is especially relevant for products that rely on NFSv3 boot flows or ship U-Boot-based firmware in exposed or field-deployed devices.

Technical summary

The NVD record classifies the weakness as CWE-787 and assigns CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The affected product criterion is denx:u-boot through 2019.07. The issue is described as an unbounded memcpy caused by a failed length check in nfs_read_reply during store_block handling in the NFSv3 case, which creates a memory-safety risk on attacker-influenced network input.

Defensive priority

Immediate. This is a critical, remotely reachable memory-corruption flaw in bootloader code and should be addressed as soon as practical in any environment that uses the affected U-Boot versions or NFS boot paths.

Recommended defensive actions

  • Upgrade U-Boot to a version newer than 2019.07 that includes the fix for CVE-2019-14198.
  • If NFS boot is not required, disable or remove the NFS boot path to reduce exposure.
  • Inventory devices and firmware images to identify any use of affected U-Boot versions.
  • Limit access to boot-time network services and isolate management or provisioning networks that may reach U-Boot NFS functionality.
  • Follow vendor and project advisories for patch availability and deployment guidance.

Evidence notes

The debrief is grounded in the NVD CVE record and the official project/vendor references listed in the source corpus. NVD identifies the affected CPE as denx:u-boot through 2019.07, classifies the weakness as CWE-787, and assigns CVSS 3.0 9.8. The description specifically cites an unbounded memcpy with a failed length check in nfs_read_reply during the NFSv3 store_block path. No exploit details are included here.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-14198 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-14198

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-14198 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-14198

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.