PatchSiren cyber security CVE debrief
CVE-2019-14203 Siemens CVE debrief
CVE-2019-14203 is a critical stack-based buffer overflow in Das U-Boot's nfs_handler reply helper function nfs_mount_reply. The issue is described as affecting U-Boot through 2019.07 and is rated CVSS 9.8, reflecting high impact with network access, no privileges, and no user interaction required.
- Vendor
- Siemens
- Product
- RUGGEDCOM ROX MX5000
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Teams that build, ship, or maintain U-Boot-based firmware should prioritize this issue, especially where NFS-related boot functionality is used or exposed. Security teams tracking embedded device bootloaders and OEM firmware updates should also review it.
Technical summary
NVD classifies CVE-2019-14203 as CWE-787 and describes a stack-based buffer overflow in the nfs_handler reply helper function nfs_mount_reply in Das U-Boot through 2019.07. The published CVSS v3.0 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a remotely reachable condition with no privileges or user interaction and potential high impact to confidentiality, integrity, and availability.
Defensive priority
High. The combination of a critical CVSS score, network reachability, and no authentication or user interaction makes this a strong patch-priority item for any environment that depends on affected U-Boot versions.
Recommended defensive actions
- Inventory firmware and images that include Das U-Boot versions through 2019.07.
- Apply the vendor or upstream U-Boot update that addresses CVE-2019-14203, using the linked advisory and repository references to identify the fixed release or commit.
- If immediate patching is not possible, minimize exposure of affected boot paths and review whether NFS-related boot functionality is required in deployed builds.
- Validate updated firmware in a staging environment before rollout to ensure boot reliability is preserved.
- Track downstream device/vendor advisories for packaged U-Boot updates and rebuilds.
Evidence notes
All core claims are supported by the supplied NVD record and linked references: the vulnerability description names a stack-based buffer overflow in nfs_mount_reply, the affected version range is through 2019.07, the weakness is CWE-787, and the CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The supplied enrichment marks this as not listed in KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-14203 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-14203
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-14203 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-14203
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.