India's largest platform and marketplace for GCCs & AI

Sign in

India's largest platform and marketplace for GCCs & AI

3AI Digital Library

IoT devices at risk from Amnesia:33

3AI December 11, 2020

A new series of vulnerabilities dubbed Amnesia:33 puts millions of IoT devices at risk of being compromised.

Security researchers from Forescout disclosed the 33 vulnerabilities today. The flaws are found in four open-source TCP/IP libraries used in the firmware of products from over 150 vendors.

According to the researchers’ estimates, millions of consumer and enterprise IoT devices are at risk from Amnesia:33 vulnerabilities.

The affected libraries are uIP, FNET, picoTCP, and Nut/Net. Manufacturers have used these libraries for decades to add TCP/IP support to their products.

Here are the number of vulnerabilities discovered in each library:

  • uIP – 13
  • picoTCP – 10
  • FNET – 5
  • Nut/Nut – 5

uIP, the most vulnerable library, was also found to be used in the highest number of vendors.

Forescout also analysed the following libraries but did not find any vulnerabilities: lwIP, CycloneTCP, and uC/TCP-IP. 

Due to the prevalence of these libraries, just about every type of connected hardware is impacted by Amnesia:33—from SoCs to smart plugs, from IP cameras to servers.

Unlike the previously disclosed Ripple20 vulnerabilities, Amnesia:33 primarily affects the DNS, TCP, and IPv4/IPv6 sub-stacks.

Ripple20 and Amnesia:33 vulnerabilities both predominately consist of Out-of-Bounds Read, followed by Integer Overflow.

IoT devices (46%) represent the highest number of affected device types, according to Forescout’s research. This is followed by OT/BAS and OT/ICS at 19 percent, and then IT at 16 percent.

(Disclaimer: The opinions expressed in this column are that of the writer. The facts and opinions expressed here do not reflect the views of www.xtechalpha.com.)

    3AI Trending Articles

  • Unlocking HR Potential: The Transformative Benefits of Generative AI in Human Resources

    Featured Article: Author: Vipin Verma, Orange Business Services Introduction to Generative AI in Human Resources Human Resources (HR) is a critical function in any organization, responsible for managing and developing the most valuable asset: the workforce. With the advancements in technology, particularly in the field of Artificial Intelligence (AI), HR has the opportunity to unlock […]

  • Driving innovation in B2B payments through AI

    Featured Article: Author:  Shireen Ali, Senior Vice President – Analytics, Citi The B2B payments sector is estimated to be a $120 trillion* business. Yet, despite recent technological advancements,  B2B payments still falls behind its counterpart, B2C,  in terms of both customer experience and efficiency. If you have to go out to a café and buy […]

  • Future of HR redefined by AI

    Artificial intelligence is transforming our lives at home and at work. At home, you may be one of the 1.8 million people who use Amazon’s Alexa to control the lights, unlock your car, and receive the latest stock quotes for the companies in your portfolio. In total, Alexa is touted as having more than 3,000 skills […]

  • Lessons in Failing to Apply Blockchain to combat C19

    This year 2020 has seen quite a variety of exciting developments in the blockchain space. To name just a few: the emergence of decentralized finance (DeFi) and non-fungible tokens (NFTs) as major economic forces and sources of crypto network user tractions, the maturation of layer 2 Ethereum solutions and the rollout of a variety of […]