Hundreds of Millions of IoT Devices at Risk Due to ‘Ripple20’ Vulnerabilities, Claim Security Researchers

Must read

Why A Cougar Probably Won’t ‘Stalk’ You — And What To Do If It Does

Chances are, the cougars aren’t after you.  But you would have been hard-pressed to tell that to Kyle Burgess on Saturday, when...

How to disable and delete Samsung Pay from your Galaxy phone

When it comes to paying conveniently, Samsung Pay makes using your phone as a bank card an easy process; however, there may come...

Games of the Generation: Stardew Valley is a welcome break from the chaos of the world

Games of the GenerationAs we approach the launch of the PS5 and Xbox Series X, TechRadar is looking back at the games that...
Bhawani Singhhttps://techmepro.com
I am a blogger who believes in delivering latest tech news from around the world to my viewers.

Security researchers have found as many as 19 zero-day vulnerabilities that affect not one or two but hundreds of millions of Internet of Things (IoT) devices globally. The vulnerabilities that are given the name Ripple20, exist in connected devices offered by various companies including Caterpillar, Cisco, HP, Intel, Rockwell Automation, Schneider Electric, among others. Also, the gadgets that are impacted by the security loopholes are powering operations at various industries — from medical and transportation to telecom and retail.

Israeli security research firm JSOF has revealed that Ripple20 vulnerabilities were identified in code offered by Ohio-based software company Treck, which provides its solutions to a large number of IoT device manufacturers. JSOF researchers found the issues in Treck’s low-level TCP/ IP software library. The loopholes were detected through an extensive, in-depth analysis of over many months, the firm wrote in a detailed post on its website.


The vulnerabilities discovered by JSOF are claimed to allow attackers to bypass Network address translation (NAT) and firewalls and take control of devices remotely, without requiring any explicit permissions from users. “This is due to the vulnerabilities’ being in a low-level TCP/IP stack, and the fact that for many of the vulnerabilities, the packets sent are very similar to valid packets, or, in some cases are completely valid packets,” the security researchers at JSOF said.

According to the researchers, the affected library exists in various industrial devices, power grids, medical equipment, home automation solutions, routers, enterprise devices, and various other IoT offerings. A proof-of-concept has been provided in a video showing how the Ripple20 vulnerabilities can be exploited by an attacker.

In an advisory released by the US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday, six of the 19 vulnerabilities discovered in the Treck code are rated between seven and 10 on the CVSS score, where 10 represents the highest severity. Two of them are even scored 10 out of 10, as noted by Wired.


Treck released a statement to confirm that it had provided patches for all the Ripple20 vulnerabilities to their clients.

The exact number of IoT devices affected by the bugs is unclear. However, JSOF contacted all the vendors of affected devices that it was able to confirm starting February. Many of them also released software updates to fix the issues. However, it is quite likely that some of the devices would still remain unpatched for several months due to the fact that some of the vendors have closed their operations, and various industry consumers are yet to update their devices using the latest patches.

Among the vendors, HP and Intel have confirmed to Wired that they were aware of the issues and were monitoring the situation. Intel also confirmed that it had fixed four of the vulnerabilities reported by JSOF through an update released earlier this month.


Is Mi Notebook 14 series the best affordable laptop range for India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

Source link

More articles

Leave a Reply

Subscribe to our newsletter

To be updated with all the latest news, offers and special announcements.

- Advertisement -

Latest article

Satellites picture methane across the globe

The GHGSat company releases a tool to show how methane varies in the atmosphere across the world. Source link

US says Google breakup may be needed to end violations of antitrust law

The Justice Department lawsuit could lead to the break-up of an iconic company that has become all but synonymous with the internet and...

How to Turn Off Your Webcam and Microphone on Zoom

While on a Zoom call, you may want to turn off your webcam’s video and mute the audio from your microphone for a...

US Congresswomen Alexandria Ocasio-Cortez, Ilhan Omar Streamed Among Us in Twitch Debut

US Congresswomen Alexandria Ocasio-Cortez (AOC) and Ilhan Omar went live on game streaming platform Twitch earlier today to play space-themed, multiplayer social deduction...

Speedify VPN review | TechRadar

Making use of a VPN almost always cuts your internet speeds, which is no real surprise given all that encryption overhead.Speedify aims to...
- Advertisement -