PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-14200 Siemens CVE debrief

CVE-2019-14200 is a critical stack-based buffer overflow in Das U-Boot's NFS reply helper rpc_lookup_reply, affecting versions through 2019.07. Because the vulnerable path is network reachable and requires no authentication or user interaction, affected bootloader deployments should treat it as urgent.

Vendor
Siemens
Product
RUGGEDCOM ROX MX5000
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

OEMs, firmware maintainers, and operators of systems that use U-Boot for network booting or NFS-based boot workflows, especially where the bootloader is exposed on trusted or semi-trusted networks.

Technical summary

NVD describes a stack-based buffer overflow in the nfs_handler reply helper function rpc_lookup_reply, with affected CPE coverage for denx:u-boot through 2019.07. The published CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8), indicating a remotely reachable flaw with no privileges or user interaction required and high impact if triggered.

Defensive priority

Urgent. This is a critical, remotely reachable memory corruption issue in a foundational boot component; exposure during network boot or NFS reply handling can put firmware integrity and availability at risk.

Recommended defensive actions

  • Upgrade to a U-Boot release or vendor backport that removes the vulnerable rpc_lookup_reply/NFS reply handling flaw.
  • If you cannot patch immediately, disable or restrict NFS/network boot paths that rely on the affected U-Boot code.
  • Limit access to boot services to trusted management networks and isolate them from general-purpose network segments.
  • Inventory downstream firmware, board support packages, and OEM images that embed U-Boot through 2019.07 and verify whether the fix was backported.
  • Watch for unexpected bootloader crashes or repeated boot failures on systems that use NFS-based booting.

Evidence notes

The supplied NVD record states that Das U-Boot through 2019.07 is affected and classifies the flaw as CWE-787. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. References in the record include a Semmle advisory, the U-Boot GitLab repository, and a Siemens product security advisory. No fixed version is provided in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-14200 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-14200

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-14200 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-14200

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.