« Volver al listado

CVE-2019-13106

Estado: ModificadaAlta (7.8)—

Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-13106",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 8.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:C",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 8.5,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX MX5000",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX MX5000RE",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX RX1400",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX RX1500",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX RX1501",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX RX1510",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX RX1511",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX RX1512",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX RX1524",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX RX1536",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM ROX RX5000",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V2.17.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2019-08-06T20:15:12.110",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00002.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00004.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://gist.github.com/deephooloovoo/d91b81a1674b4750e662dfae93804d75",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/u-boot/u-boot/commits/master",
      "tags": [
        "Product"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.denx.de/pipermail/u-boot/2019-July/375516.html",
      "tags": [
        "Mailing List",
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00002.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00004.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gist.github.com/deephooloovoo/d91b81a1674b4750e662dfae93804d75",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/u-boot/u-boot/commits/master",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.denx.de/pipermail/u-boot/2019-July/375516.html",
      "tags": [
        "Mailing List",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/html/ssa-577017.html",
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution."
    },
    {
      "lang": "es",
      "value": "Das U-Boot versiones 2016.09 hasta 2019.07-rc4, pueden memorizar en la función memset() muchos datos mientras leen un sistema de archivos ext4 diseñado, lo que resulta en un desbordamiento del búfer de la pila y una posible ejecución de código."
    }
  ],
  "lastModified": "2026-06-17T02:16:04.230",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6671B486-515C-4F5D-B286-7B473109B301",
              "versionEndIncluding": "2019.04",
              "versionStartIncluding": "2016.09"
            },
            {
              "criteria": "cpe:2.3:a:denx:u-boot:2019.07:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01EA00F5-7A9D-4EB9-A852-047EA72084E8"
            },
            {
              "criteria": "cpe:2.3:a:denx:u-boot:2019.07:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75689E3C-FBB6-46B5-B59C-41D244702158"
            },
            {
              "criteria": "cpe:2.3:a:denx:u-boot:2019.07:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9358D79B-256E-4AEA-BE6B-A182AA4AE861"
            },
            {
              "criteria": "cpe:2.3:a:denx:u-boot:2019.07:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6AAFACF6-606C-4429-B680-01D3C4A98BC1"
            },
            {
              "criteria": "cpe:2.3:a:denx:u-boot:2019.07:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27B38F3B-75C0-4067-857F-C78160493D17"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1E78106-58E6-4D59-990F-75DA575BFAD9"
            },
            {
              "criteria": "cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B620311B-34A3-48A6-82DF-6F078D7A4493"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}