RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Monday, August 10, 2026
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Add RCR Wireless as a preferred source on Google
  • Qualcomm 6G Insights
  • Huawei Content Hub
  • Qualcomm – 6G Vision
  • OSS/BSS Channel
  • RCRTech Roundtable: AI Infrastructure
RCR Wireless
RCR Wireless
  • Advanced Mimo
  • Mobile mmWave
  • 5G Positioning
  • Green Networks
  • Metaverse
  • Automotive
  • Industrial and Wide-area IoT
Copyright 2021 - All Right Reserved
Home - Potentially billions of IoT devices at risk from Ripple20 attacks – major brands are flagged
Internet of Things (IoT)News & Event CoverageSecuritySensorsSmart CitiesSmart FactoryWired Networks, Fiber

Potentially billions of IoT devices at risk from Ripple20 attacks – major brands are flagged

by James Blackman June 18, 2020
written by James Blackman June 18, 2020 Share
LinkedinEmail
Share 0LinkedinEmail
186

Security experts have identified a series of 19 vulnerabilities, given the name Ripple20, in a small software library integrated into “hundreds of millions”, and potentially billions, of IoT devices that have been sold into consumer, enterprise and industrial markets during the past two decades.

Israeli security firm JSOF said this week that IoT devices from Caterpillar, Cisco, HP, HPE, Intel, Rockwell, Schneider Electric, and Digi, among others, are vulnerable to remote hacks by cyber-criminals. The vulnerable TCP/IP software stack was sold by an Ohio-based software company called Treck.

JSOF said it had struggled to track down the software library in the supply chain, calling it a “major challenge”. It said: “Many other major international vendors suspected of being of vulnerable in medical, transportation, industrial control, enterprise, energy, telecom, retail and commerce, and other industries,” it said.

Devices from the likes of BAE Systems, Broadcom, Fraunhofer, Itron, Lockheed Martin, Marvell, and NVIDIA remain under investigation. Devices by Amd, GE Healthcare, Laird, Philips, Texas Instruments, and Zebra Technologies have been confirmed as unaffected.

Most of the “zero-day” vulnerabilities in the code are caused by memory management bugs, and date back to the 1990s. JSOF stated: “The number of devices that contain the vulnerable code base library is only a preliminary estimate; the number may realistically be in the billions.”

Ripple20The software has “spread around the world” during the past two decades, it said. “As a dissemination vector, the complex supply chain provides the perfect channel, making it possible for the original vulnerability to infiltrate and camouflage itself almost endlessly.”

All organisations must perform a comprehensive risk assessment before deploying defensive measures, said JSOF. (Its full recommendation is contained on its website.) Treck, which worked with JSOF on the research, recommends users upgrade to the latest stable version of its software stack (version 6.0.1.67 or later).

JSOF has highlighted the “extent of [the] impact, magnified by the supply chain factor”; its name was given for its ripple-effect across the supply chain. JSOF said: “In all scenarios, an attacker can gain complete control over the targeted device remotely, with no user interaction required.”

It added: “The risks inherent in this situation are high… A single vulnerable component, though it may be relatively small in and of itself, can ripple outward to impact a wide range of industries, applications, companies, and people.”

Affected Industries v2It highlighted certain examples: data could be accessed and stolen remotely from printers, infusion pumps, and industrial control devices, it said. “An attacker could hide malicious code within embedded devices for years. One of the vulnerabilities could enable entry from outside into the network boundaries; and this is only a small taste of the potential risks.”

JSOF will issue a white-paper on its findings at BlackHat USA 2020 in August.

The US Cybersecurity and Infrastructure Security Agency (CISA) said it is aware of the vulnerabilities, and flagged Treck’s upgrade path. It also said users should take certain defensive measures to minimise the risk of exploitation of this vulnerability.

Natali Tshuva, chief executive at Sternum, another Israeli cyber-security firm, commented: “The Ripple20 vulnerabilities in IoT devices are significant and widespread, making data and device security the most important IoT cybersecurity issue of our time.

“What’s even more problematicis the fact that the affected library wasn’t only used by IoT device vendors directly, but also integrated into software suites, meaning that many companies using this software are not aware that they are using this particular piece of code. Because of these third-party vulnerabilities, major vendors are now exposed to potential damage and financial loss

“Ultimately, only IoT device manufacturers can solve these cybersecurity issues, as companies that deploy IoT devices are typically unable to install protection or update the security of the devices. This is why we are seeing (and will continue to see) legislation and regulations moving towards shifting liability onto the device manufacturers themselves.”

You Might Also Like
  • Bell advances AIDC strategy as fiber and enterprise AI drive Q2
  • Physical AI is exposing a data sovereignty gap (Reader Forum)
  • Japan’s private 5G market is finally moving beyond demo experiments (Analyst Angle)
  • Hollow-core fiber won’t hit cost parity for a decade – regarding HKT’s 3.2Tbps DCI ‘superhighway’
  • AI drives new demands on optical networks, Ciena says
  • Monday (telco diary) | Sovereign AI for Industry 4.0
Share 0 LinkedinEmail
James Blackman
James Blackman

James Blackman has been writing about the technology and telecoms sectors for over a decade. He has edited and contributed to a number of European news outlets and trade titles. He has also worked at telecoms company Huawei, leading media activity for its devices business in Western Europe. He is based in London.

previous post
#TBT: Automakers go high-tech; Nvidia’s Kal-El ‘super chip’; RIM teeters … this week in 2011
next post
Why short-range and wide-area IoT make a marriage of perfect convenience

White Papers

  • Norton eBook: The 2026 Telco Playbook

  • Enea White Paper: Why Intelligent AAA is the Swiss Army Knife of Telecom

  • CSG White Paper: Telco AI Enabler: Mediation’s Defining Role

  • Enea White Paper: Scalable Database Design for 5G and Beyond

  • Supermicro and NVIDIA Whitepaper: Powering sovereign AI at scale

Editorial Reports

  • Report: NTN in motion — evolving standards, expanding services

  • Market Pulse Report: Telco AI in 2026 – Trends, Challenges and Opportunities

  • Nvidia Report: The State of AI in Telecommunications: 2026 Trends

Webinars

  • Webinar: Building 6G — aligning technology, policy and purpose

  • SIMCom Webinar: Scaling your next deployment – from plastic to provisioning

  • Webinar: Rethinking the RAN as AI, cloud and openness converge

  • Webinar: Scale-Up, Scale-Out, Scale-Across – Building AI-Era Network Fabrics

  • Webinar: NTN in motion – evolving standards, expanding services

Since 1982, RCR Wireless News has been providing wireless and mobile industry news, insights, and analysis to mobile and wireless industry professionals, decision makers, policy makers, analysts and investors.

Facebook Twitter Youtube Linkedin Envelope Rss

Useful Links

  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive
  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive

Edtior's Picks

‘We think of them as hometown ISPs’ – WISPA chief on BEAD, Starlink,...
Friday (telco diary) | Friday night fare – private 5G to go
The Agentic Network — NVIDIA on the full-stack path to telecom autonomy

Latest Articles

‘We think of them as hometown ISPs’ – WISPA chief on BEAD, Starlink, CBRS
Friday (telco diary) | Friday night fare – private 5G to go
The Agentic Network — NVIDIA on the full-stack path to telecom autonomy
Ericsson named sole global tech partner in SK Telecom-led AI-RAN pilot

© 2026 RCR Wireless News All Right Reserved. Developed by Eight Hats.

Cookie Policy | Privacy Policy

RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
@2020 - All Right Reserved. Designed and Developed by PenciDesign