CVE-2019-14194 is a critical vulnerability affecting Das U-Boot through version 2019.07, stemming from an unbounded memcpy in the nfs_read_reply function during NFSv2 operations. With a CVSS score of 9.8, this flaw allows for remote, unauthenticated attacks with high impact on confidentiality, integrity, and availability. While there is no known active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion, indicating potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2019.07CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.