Ripple20 Critical Vulnerabilities – Detection Logic and Signatures
ID: 1f8dc227-f5bf-5f1d-91d4-4e4fd599de60
STIX ID: report--1f8dc227-f5bf-5f1d-91d4-4e4fd599de60
Feed Name: McAfee Labs Blog
Threat Score
This McAfee Advanced Threat Research / JSOF report analyzes multiple critical vulnerabilities in the Treck TCP/IP stack (Ripple20), including CVE-2020-11901 (DNS heap overflows variants), CVE-2020-11897 (IPv6 RH0 out-of-bounds), and CVE-2020-11896 (IPv4/UDP tunneling RCE). It documents technical root causes, limitations and detection challenges, and provides recommended detection criteria plus Suricata rules and Lua scripts to help identify exploitation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
