HomeSecurityRipple20 vulnerabilities will haunt the IoT landscape in 2020

Ripple20 vulnerabilities will haunt the IoT landscape in 2020

Cybersecurity experts today disclosed 19 vulnerabilities – which they dubbed Ripple20 – in a small library designed in the 1990s and which has been used and integrated into countless enterprise and consumer products for the past 20+ years.

Ripple20

Products affected include smart home devices, power grid equipment, healthcare systems, industrial tools, transportation systems, printers, routers, mobile/satellite communications equipment, data center devices, aircraft devices, various enterprise solutions, and more.

Experts now fear that all products using this library will likely remain unpatched due to complex or untracked software supply chains.

Problems arise from the fact that the library was not only used by hardware vendors but was also integrated into other software suites, meaning that many companies are not even aware that they are using this particular piece of code , and the name of the vulnerable library does not appear in the code.

 Ripple20 vulnerabilities

These vulnerabilities – referred to as Ripple20 – affect a small library developed by Cincinnati-based software company Treck.

The library, believed to have first been released in 1997, implements a TCP/IP stack. Companies have been using this library for decades to allow their devices or software to connect to the Internet over TCP/IP connections.

Since September 2019, researchers from JSOF, a small cybersecurity consulting firm based in Israel, have been examining Treck's TCP/IP stack, due to its proliferation across the industrial, healthcare, and smart device markets.

The company discovered and collaborated with CERTs in various countries to coordinate the process of disclosing and fixing the vulnerability.

In an interview with ZDNet last week, JSOF said that this operation involved a lot of work and different steps, such as ensuring that was notified and finding all the vulnerable equipment and contacting each of the affected vendors.

The efforts were successful, JSOF CEO told ZDNet. The CEO credited CERT/CC for playing a key role in coordinating the vulnerability notification process for all affected vendors.

Treck, while wary at first and believing she was the subject of an extortion attempt, is now fully informed, said the JSOF CEO.

Treck confirmed that patches are now available for all Ripple20 vulnerabilities.

However, JSOF said that the identification of all vulnerable devices is not yet complete. The researchers said that they named the 19 vulnerabilities Ripple20 not because they were 20 vulnerabilities to begin with, but because of the impact they will have on the IoT landscape in 2020 and beyond.

Oberman said that while not all of Ripple20's vulnerabilities are serious, there are some that are extremely dangerous, allowing attackers to take over vulnerable systems from a "remote" scenario.

The US Department of Homeland Security assigned scores of 10 and 9.8 on the CVSSv3 vulnerability severity scale (the scale ranges from 1 to 10) to four of the Ripple 20 vulnerabilities. These are the following:

  • CVE-2020-11896 – CVSSv3 score: 10
  • CVE-2020-11897 – CVSSv3 score: 10
  • CVE-2020-11898 – CVSSv3 score: 9.8
  • CVE-2020-11899 – CVSSv3 score: 9.8

These four vulnerabilities could allow attackers to easily take control of smart devices or any industrial or healthcare equipment. Attacks can be carried out over the internet if the devices are connected to the internet, or from local networks if the attacker gains access to an internal network (for example, through a compromised router).

These four vulnerabilities are ideal for both botnet operators and targeted attacks. Checking all systems for Ripple20 vulnerabilities and patching these four issues in particular should be a priority for all companies.

JSOF was invited to speak about these vulnerabilities at the Black Hat USA 2020 security conference.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS