← Vulnerability feed

Vulnerability record · CVE-2019-17006 · published 22 October 2020

CVE-2019-17006: Siemens ruggedcom rox mx5000 firmware improper input validation vulnerability

Siemens · Ruggedcom Rox Mx5000 Firmware

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

9.8 CVSS 3.1 Critical EPSS 3.6% · top 11.1% CWE-20 · Improper input validationCWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score, v2 10.0
3.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
10References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-17006 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-22555Linux kernel netfilter x_tables heap out-of-bounds writeA heap out-of-bounds write exists in the Linux kernel netfilter x_tables code (net/netfilter/x_tables.c), present since v2.6.19-rc1. A local attacker…KEVEPSS 79%analysed7.8CVE-2021-3156Sudo off-by-one heap overflow allows root privilege escalationSudo before 1.9.5p2 contains an off-by-one error leading to a heap-based buffer overflow. Triggering it via 'sudoedit -s' with a command-line argumen…KEVEPSS 100%analysed7.8CVE-2019-2215Android Binder use-after-free allows kernel privilege escalationCVE-2019-2215 is a use-after-free in binder.c in the Android/Linux kernel that lets a local application escalate privileges to the kernel. It matters…KEVEPSS 72%analysed7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed7.0CVE-2016-5195Linux Kernel Dirty COW Race Condition Privilege EscalationA race condition in the Linux kernel's mm/gup.c mishandles copy-on-write, letting a local user write to read-only memory mappings. This breaks the re…KEVEPSS 84%analysed10.0CVE-2014-1544Mozilla firefox vulnerabilityUse-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox…EPSS 6.1%9.8CVE-2024-56171Xmlsoft libxml2 use after free vulnerabilitylibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. …EPSS 1.2%9.8CVE-2022-37434Zlib out-of-bounds write vulnerabilityzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only appl…EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2019-17006), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.