RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Saturday, September 12, 2026
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Add RCR Wireless as a preferred source on Google
  • Qualcomm 6G Insights
  • Huawei Content Hub
  • Qualcomm – 6G Vision
  • OSS/BSS Channel
  • RCRTech Roundtable: AI Infrastructure
RCR Wireless
RCR Wireless
  • Advanced Mimo
  • Mobile mmWave
  • 5G Positioning
  • Green Networks
  • Metaverse
  • Automotive
  • Industrial and Wide-area IoT
Copyright 2021 - All Right Reserved
Home - Potentially billions of IoT devices at risk from Ripple20 attacks – major brands are flagged
Internet of Things (IoT)News & Event CoverageSecuritySensorsSmart CitiesSmart FactoryWired Networks, Fiber

Potentially billions of IoT devices at risk from Ripple20 attacks – major brands are flagged

by James Blackman June 18, 2020
written by James Blackman June 18, 2020 Share
LinkedinEmail
Share 0LinkedinEmail
232

Security experts have identified a series of 19 vulnerabilities, given the name Ripple20, in a small software library integrated into “hundreds of millions”, and potentially billions, of IoT devices that have been sold into consumer, enterprise and industrial markets during the past two decades.

Israeli security firm JSOF said this week that IoT devices from Caterpillar, Cisco, HP, HPE, Intel, Rockwell, Schneider Electric, and Digi, among others, are vulnerable to remote hacks by cyber-criminals. The vulnerable TCP/IP software stack was sold by an Ohio-based software company called Treck.

JSOF said it had struggled to track down the software library in the supply chain, calling it a “major challenge”. It said: “Many other major international vendors suspected of being of vulnerable in medical, transportation, industrial control, enterprise, energy, telecom, retail and commerce, and other industries,” it said.

Devices from the likes of BAE Systems, Broadcom, Fraunhofer, Itron, Lockheed Martin, Marvell, and NVIDIA remain under investigation. Devices by Amd, GE Healthcare, Laird, Philips, Texas Instruments, and Zebra Technologies have been confirmed as unaffected.

Most of the “zero-day” vulnerabilities in the code are caused by memory management bugs, and date back to the 1990s. JSOF stated: “The number of devices that contain the vulnerable code base library is only a preliminary estimate; the number may realistically be in the billions.”

Ripple20The software has “spread around the world” during the past two decades, it said. “As a dissemination vector, the complex supply chain provides the perfect channel, making it possible for the original vulnerability to infiltrate and camouflage itself almost endlessly.”

All organisations must perform a comprehensive risk assessment before deploying defensive measures, said JSOF. (Its full recommendation is contained on its website.) Treck, which worked with JSOF on the research, recommends users upgrade to the latest stable version of its software stack (version 6.0.1.67 or later).

JSOF has highlighted the “extent of [the] impact, magnified by the supply chain factor”; its name was given for its ripple-effect across the supply chain. JSOF said: “In all scenarios, an attacker can gain complete control over the targeted device remotely, with no user interaction required.”

It added: “The risks inherent in this situation are high… A single vulnerable component, though it may be relatively small in and of itself, can ripple outward to impact a wide range of industries, applications, companies, and people.”

Affected Industries v2It highlighted certain examples: data could be accessed and stolen remotely from printers, infusion pumps, and industrial control devices, it said. “An attacker could hide malicious code within embedded devices for years. One of the vulnerabilities could enable entry from outside into the network boundaries; and this is only a small taste of the potential risks.”

JSOF will issue a white-paper on its findings at BlackHat USA 2020 in August.

The US Cybersecurity and Infrastructure Security Agency (CISA) said it is aware of the vulnerabilities, and flagged Treck’s upgrade path. It also said users should take certain defensive measures to minimise the risk of exploitation of this vulnerability.

Natali Tshuva, chief executive at Sternum, another Israeli cyber-security firm, commented: “The Ripple20 vulnerabilities in IoT devices are significant and widespread, making data and device security the most important IoT cybersecurity issue of our time.

“What’s even more problematicis the fact that the affected library wasn’t only used by IoT device vendors directly, but also integrated into software suites, meaning that many companies using this software are not aware that they are using this particular piece of code. Because of these third-party vulnerabilities, major vendors are now exposed to potential damage and financial loss

“Ultimately, only IoT device manufacturers can solve these cybersecurity issues, as companies that deploy IoT devices are typically unable to install protection or update the security of the devices. This is why we are seeing (and will continue to see) legislation and regulations moving towards shifting liability onto the device manufacturers themselves.”

You Might Also Like
  • Nokia says AI pushes optical networks into the scale-across era
  • Ciena sees AI driving multi-year optical infrastructure investment cycle
  • AI pushes fiber networks toward a capacity crunch, AFL says
  • Fiber becomes AI’s next bottleneck
  • Bell advances AIDC strategy as fiber and enterprise AI drive Q2
  • Physical AI is exposing a data sovereignty gap (Reader Forum)
Share 0 LinkedinEmail
James Blackman
James Blackman

James Blackman has been writing about the technology and telecoms sectors for over a decade. He has edited and contributed to a number of European news outlets and trade titles. He has also worked at telecoms company Huawei, leading media activity for its devices business in Western Europe. He is based in London.

previous post
#TBT: Automakers go high-tech; Nvidia’s Kal-El ‘super chip’; RIM teeters … this week in 2011
next post
Why short-range and wide-area IoT make a marriage of perfect convenience

White Papers

  • Norton eBook: The 2026 Telco Playbook

  • Enea White Paper: Why Intelligent AAA is the Swiss Army Knife of Telecom

  • CSG White Paper: Telco AI Enabler: Mediation’s Defining Role

  • Enea White Paper: Scalable Database Design for 5G and Beyond

  • Supermicro and NVIDIA Whitepaper: Powering sovereign AI at scale

Editorial Reports

  • Report: Building 6G — Aligning technology, policy and purpose

  • Report: Rethinking the RAN

  • Report: Building AI-Era Network Fabrics

Webinars

  • Appledore Webinar: Closing the Agent-Ready Data Gap for Autonomous Networks

  • Mimosa Webinar – Build the Right Network

  • Webinar: Building 6G — aligning technology, policy and purpose

  • SIMCom Webinar: Scaling your next deployment – from plastic to provisioning

  • Webinar: Rethinking the RAN as AI, cloud and openness converge

Since 1982, RCR Wireless News has been providing wireless and mobile industry news, insights, and analysis to mobile and wireless industry professionals, decision makers, policy makers, analysts and investors.

Facebook Twitter Youtube Linkedin Envelope Rss

Useful Links

  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive
  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive

Edtior's Picks

Metro fiber, “kick-ass” 5G, a little DCI and D2D – AT&T sets its...
Nokia hints at new campus-AI strategy, raises questions about its old campus-5G one
American Tower sees AI, 5G, and spectrum driving infra demand

Latest Articles

Metro fiber, “kick-ass” 5G, a little DCI and D2D – AT&T sets its course
Nokia hints at new campus-AI strategy, raises questions about its old campus-5G one
American Tower sees AI, 5G, and spectrum driving infra demand
High bandwidth, high fidelity: Vertex 6.0 delivers emulation for ISAC, 6G and more

© 2026 RCR Wireless News All Right Reserved. Developed by Eight Hats.

Cookie Policy | Privacy Policy

RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
@2020 - All Right Reserved. Designed and Developed by PenciDesign