logo

Ripple20 Critical Vulnerabilities – Detection Logic and Signatures

ID: 1f8dc227-f5bf-5f1d-91d4-4e4fd599de60

STIX ID: report--1f8dc227-f5bf-5f1d-91d4-4e4fd599de60

Feed Name: McAfee Labs Blog

Threat Score
85/100

Date Published: 2020-08-05

Date Updated: 2026-04-28

Author: Steve Povolny

...
...

This McAfee Advanced Threat Research / JSOF report analyzes multiple critical vulnerabilities in the Treck TCP/IP stack (Ripple20), including CVE-2020-11901 (DNS heap overflows variants), CVE-2020-11897 (IPv6 RH0 out-of-bounds), and CVE-2020-11896 (IPv4/UDP tunneling RCE). It documents technical root causes, limitations and detection challenges, and provides recommended detection criteria plus Suricata rules and Lua scripts to help identify exploitation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.