CVE-2019-14199 is a critical vulnerability affecting Das U-Boot through version 2019.07, stemming from an unbounded memcpy operation during UDP packet parsing due to an integer underflow. With a CVSS score of 9.8, this vulnerability allows for remote, unauthenticated attacks with high impact on confidentiality, integrity, and availability. Despite its severity, there is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2019.07CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.