{"id":35553,"date":"2020-06-16T19:09:50","date_gmt":"2020-06-16T19:09:50","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/31303\/Ripple20-Vulnerabilities-Will-Haunt-The-IoT-Landscape-For-Years-To-Come.html"},"modified":"2020-06-16T19:09:50","modified_gmt":"2020-06-16T19:09:50","slug":"ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/","title":{"rendered":"Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come"},"content":{"rendered":"<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/2020\/06\/16\/eb2cf961-15dd-481a-a17e-9bd9c9ee05fd\/ripple20.png\" class alt=\"Ripple20\"><\/span><\/p>\n<p>Cyber-security experts have revealed today 19 vulnerabilities in a small library designed in the 90s that has been widely used and integrated into countless of enterprise and consumer-grade products over the last 20+ years.<\/p>\n<p>The number if impacted products is estimated at &#8220;hundreds of millions&#8221; and includes products such as smart home devices, power grid equipment, healthcare systems, industrial gear, transportation systems, printers, routers, mobile\/satellite communications equipment, data center devices, commercial aircraft devices, various enterprise solutions, and many others.<\/p>\n<p>Experts now fear that all products using this library will most likely remain unpatched due to complex or untracked software supply chains.<\/p>\n<p>Problems arise from the fact that the library was not only used by equipment vendors directly but also integrated into other software suites, which means that many companies aren&#8217;t even aware that they&#8217;re using this particular piece of code, and the name of the vulnerable library doesn&#8217;t appear in their code manifests.<\/p>\n<h3>The Ripple20 vulnerabilities<\/h3>\n<p>These vulnerabilities &#8212; collectively referred to as <a href=\"https:\/\/www.jsof-tech.com\/ripple20\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\"><strong>Ripple20<\/strong><\/a> &#8212; impact a small library developed by Cincinnati-based software company <a href=\"https:\/\/treck.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Treck<\/a>.<\/p>\n<p>The library, believed to have been first released in 1997, implements a lightweight TCP\/IP stack. Companies have been using this library for decades to allow their devices or software to connect to the internet via TCP\/IP connections.<\/p>\n<p>Since September 2019, researchers from <a href=\"https:\/\/www.jsof-tech.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">JSOF<\/a>, a small boutique cyber consultancy firm located in Jerusalem, Israel, have been looking at Treck&#8217;s TCP\/IP stack, due to its broad footprint across the industrial, healthcare, and smart device market.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>Their work unearthed serious vulnerabilities, and the JSOF team has been working with CERT (computer emergency response teams) in different countries to coordinate the vulnerability disclosure and patching process.<\/p>\n<p>In an interview with <em>ZDNet<\/em> last week, JSOF said this operation involved a lot of work and different steps, such as getting Treck on board, making sure Treck has patches on time, and then finding all the vulnerable equipment and reaching out to each of the impacted vendors.<\/p>\n<p>Efforts have been successful, Shlomi Oberman, chief executive officer at JSOF, has told <em>ZDNet<\/em>. Oberman credited CERT\/CC for playing a major role in coordinating the vulnerability disclosure process with all impacted vendors.<\/p>\n<p>Treck, while reticent in the beginning and thinking it was the subject of an extortion attempt, is now fully on board, Oberman said.<\/p>\n<p>In an email to <em>ZDNet<\/em> on Monday, Treck has confirmed that patches are now available for all the Ripple20 vulnerabilities.<\/p>\n<h3>Work on Ripple20 only halfway done<\/h3>\n<p>But JSOF said the work on identifying all the vulnerable devices is not yet done. The researchers said they named the 19 vulnerabilities as Ripple20 not because they were 20 vulnerabilities in the beginning, but because of the ripple effect they&#8217;ll cause in the IoT landscape in 2020, and the years to come.<\/p>\n<p>Researchers say they only scratched the surface when it comes to discovering all the devices that have implemented Treck&#8217;s TCP\/IP library, and that many equipment vendors will need to verify their own code going forward.<\/p>\n<p>Oberman said that while not all of the Ripple20 vulnerabilities are severe, there are a few that are extremely dangerous, allowing attackers to take over vulnerable systems from a &#8220;remote&#8221; scenario.<\/p>\n<p>In a security advisory that will go live today and reviewed by ZDNet under embargo, the US Department of Homeland Security has attributed ratings of 10 and 9.8 on the CVSSv3 vulnerability severity scale (scale goes from 1 to 10) to four of the Ripple 20 vulnerabilities. These are:<\/p>\n<ul>\n<li><strong>CVE-2020-11896<\/strong> &#8211; CVSSv3 score: 10 &#8211; Improper handling of length parameter inconsistency in IPv4\/UDP component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution.<\/li>\n<li><strong>CVE-2020-11897<\/strong> &#8211; CVSSv3 score: 10 &#8211; Improper handling of length parameter inconsistency in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in possible out-of-bounds write.<\/li>\n<li><strong>CVE-2020-11898<\/strong> &#8211; CVSSv3 score: 9.8 &#8211; Improper handling of length parameter inconsistency in IPv4\/ICMPv4 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in exposure of sensitive information.<\/li>\n<li><strong>CVE-2020-11899<\/strong> &#8211; CVSSv3 score: 9.8 &#8211; Improper input validation in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow exposure of sensitive information.<\/li>\n<\/ul>\n<p>These four vulnerabilities, when weaponized, could allow attackers to easily take over smart devices or any industrial or healthcare equipment. Attacks are possible via the internet if the devices are connected online, or from local networks if the attacker gains a foothold on an internal network (for example, via a compromised router).<\/p>\n<p>These four vulnerabilities are ideal for both botnet operators, but also for targeted attacks. Testing all systems for the Ripple20 vulnerabilities and patching these four issues, in particular, should be a priority for all companies, primarily due to Treck&#8217;s large footprint across the software landscape.<\/p>\n<section class=\"shortcode media-source\">\n<p><iframe width=\"500\" height=\"282\" frameborder=\"0\" allowfullscreen=\"true\" title=\"YouTube content\" id=\"iframe_youtube\" class=\"optanon-category-3\" data-src=\"https:\/\/www.youtube.com\/embed\/jkfNE_Twa1s\">[embedded content]<\/iframe> <\/p>\n<\/section>\n<p>The impact of the Ripple20 vulnerabilities is currently expected to be the same as <a href=\"https:\/\/www.zdnet.com\/article\/urgent11-security-flaws-impact-routers-printers-scada-and-many-iot-devices\/\" target=\"_blank\" rel=\"noopener noreferrer\">the Urgent\/11 vulnerabilities<\/a> that were disclosed in July 2019, and which are still being investigated to this day, and new vulnerable devices are being found and patched on a regular basis. The comparison is not accidental, as the Urgent\/11 vulnerabilities impacted the the TCP\/IP (IPnet) networking stack of the VxWorks real-time operating system, another product widely used in the IoT and industrial landscape.<\/p>\n<p>Just like in the case of Urgent\/11, some products will remained unpatched, as some have gone end-of-life, or the vendors have shut down operations in the meantime.<\/p>\n<p>JSOF has been invited to speak about these vulnerabilities at the <a href=\"https:\/\/www.blackhat.com\/us-20\/briefings\/schedule\/index.html#hacking-the-supply-chain--vulnerabilities-haunt-tens-of-millions-of-critical-devices-19493\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Black Hat USA 2020 security conference.<br \/><\/a><\/p>\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-168-01\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\"><em>US-CERT<\/em><\/a><em>,<\/em> <a href=\"https:\/\/kb.cert.org\/vuls\/id\/257161\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\"><em>CERT\/CC<\/em><\/a><em>, and<\/em> <a href=\"https:\/\/treck.com\/vulnerability-response-information\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\"><em>Treck<\/em><\/a> <em>have also published advisories with details about the vulnerabilities and<\/em> <a href=\"https:\/\/github.com\/CERTCC\/PoC-Exploits\/blob\/master\/vu-257161\/recommendations.md\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\"><em>mitigation advice<\/em><\/a><em>.<\/em><\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/31303\/Ripple20-Vulnerabilities-Will-Haunt-The-IoT-Landscape-For-Years-To-Come.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":35554,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[256],"class_list":["post-35553","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackerflaw"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-06-16T19:09:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come.png\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come\",\"datePublished\":\"2020-06-16T19:09:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/\"},\"wordCount\":957,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come.png\",\"keywords\":[\"headline,hacker,flaw\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/\",\"name\":\"Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come.png\",\"datePublished\":\"2020-06-16T19:09:50+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come.png\",\"width\":770,\"height\":400},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,flaw\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerflaw\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/","og_locale":"en_US","og_type":"article","og_title":"Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-06-16T19:09:50+00:00","og_image":[{"width":770,"height":400,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come","datePublished":"2020-06-16T19:09:50+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/"},"wordCount":957,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come.png","keywords":["headline,hacker,flaw"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/","url":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/","name":"Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come.png","datePublished":"2020-06-16T19:09:50+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/06\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come.png","width":770,"height":400},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,flaw","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerflaw\/"},{"@type":"ListItem","position":3,"name":"Ripple20 Vulnerabilities Will Haunt The IoT Landscape For Years To Come"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/35553","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=35553"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/35553\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/35554"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=35553"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=35553"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=35553"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}