Hundreds of Millions of IoT Devices at Risk Due to ‘Ripple20’ Vulnerabilities, Claim Security Researchers

The security loopholes were detected through an extensive analysis of over many months, JSOF researchers claimed.

Advertisement
By Jagmeet Singh | Updated: 17 June 2020 14:03 IST
Highlights
  • JSOF found the issues in Treck’s low-level TCP/ IP software library
  • Ripple20 vulnerabilities impacted devices of Cisco, HP, and other vendors
  • Treck fixed the flaws and provided the patches to its clients

The vulnerabilities allow attackers to bypass firewalls and take control of devices remotely

Security researchers have found as many as 19 zero-day vulnerabilities that affect not one or two but hundreds of millions of Internet of Things (IoT) devices globally. The vulnerabilities that are given the name Ripple20, exist in connected devices offered by various companies including Caterpillar, Cisco, HP, Intel, Rockwell Automation, Schneider Electric, among others. Also, the gadgets that are impacted by the security loopholes are powering operations at various industries — from medical and transportation to telecom and retail.

Israeli security research firm JSOF has revealed that Ripple20 vulnerabilities were identified in code offered by Ohio-based software company Treck, which provides its solutions to a large number of IoT device manufacturers. JSOF researchers found the issues in Treck's low-level TCP/ IP software library. The loopholes were detected through an extensive, in-depth analysis of over many months, the firm wrote in a detailed post on its website.

The vulnerabilities discovered by JSOF are claimed to allow attackers to bypass Network address translation (NAT) and firewalls and take control of devices remotely, without requiring any explicit permissions from users. “This is due to the vulnerabilities' being in a low-level TCP/IP stack, and the fact that for many of the vulnerabilities, the packets sent are very similar to valid packets, or, in some cases are completely valid packets,” the security researchers at JSOF said.

Advertisement

According to the researchers, the affected library exists in various industrial devices, power grids, medical equipment, home automation solutions, routers, enterprise devices, and various other IoT offerings. A proof-of-concept has been provided in a video showing how the Ripple20 vulnerabilities can be exploited by an attacker.

Advertisement

In an advisory released by the US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday, six of the 19 vulnerabilities discovered in the Treck code are rated between seven and 10 on the CVSS score, where 10 represents the highest severity. Two of them are even scored 10 out of 10, as noted by Wired.

Treck released a statement to confirm that it had provided patches for all the Ripple20 vulnerabilities to their clients.

Advertisement

The exact number of IoT devices affected by the bugs is unclear. However, JSOF contacted all the vendors of affected devices that it was able to confirm starting February. Many of them also released software updates to fix the issues. However, it is quite likely that some of the devices would still remain unpatched for several months due to the fact that some of the vendors have closed their operations, and various industry consumers are yet to update their devices using the latest patches.

Among the vendors, HP and Intel have confirmed to Wired that they were aware of the issues and were monitoring the situation. Intel also confirmed that it had fixed four of the vulnerabilities reported by JSOF through an update released earlier this month.


Is Mi Notebook 14 series the best affordable laptop range for India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Also seeCryptocurrency Prices across Indian exchanges

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  2. Apple to Reportedly Launch Low-Cost MacBook in 'Playful Colors' in March
  3. Lava Bold N2 Will Be Launched in India on This Date: See Expected Specs
  4. Anthropic's First Indian Office in Bengaluru Is Now Open
  5. Deals on iPhone 17, Google Pixel 10 and More During Flipkart Sale
  6. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  7. Oppo Find X10 Series Could Debut This Year With This iPhone-Like Feature
  8. Samsung Galaxy A27 5G Lands on IMEI Database, Could Launch Soon
  9. AI Impact Summit: From Registration to Schedule, All You Need to Know
  10. Oppo K14x 5G With 6,500mAh Battery Goes on Sale in India: See Price, Offers
  1. X Building Smart 'Cashtags' to Let Users Check Cryptocurrency Prices in Real-Time
  2. Samsung Galaxy A27 5G Listing on IMEI Database Suggests a Galaxy A26 Successor Is on the Way
  3. Anthropic Inaugurates First Indian Office in Bengaluru, Starts Hiring Local Talent
  4. Apple Tipped to Adopt Samsung's Privacy Display Technology for MacBook Models by 2029
  5. Oppo Find X10 Series Tipped to Launch in H2 2026 With Built-In Magnets for Wireless Charging
  6. AMD and TCS to Co-Develop Helios AI Data Centre Architecture, Deliver 200MW Data Centre Blueprint
  7. Tecno Spark 50 4G Tipped to Launch Globally Soon; Design, Colourways, Key Features Leaked
  8. Lava Bold N2 India Launch Date Revealed; Will Be Exclusively Available via Amazon
  9. Government Green Lights Rs. 10,000 Crore Fund of Funds 2.0 Under the Startup India Mission
  10. Samsung’s 'Wide' Galaxy Z Fold Design Revealed via Leaked One UI 9 Animations
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.