HC3 Analyst Note TLP White - TCP/IP Stack Vulnerabilities Possibly Affect Healthcare Devices

January 4, 2020

On December 8, 2020, a report titled Amnesia:33 developed by Forescout disclosed multiple zero-day vulnerabilities in the TCP/IP stacks impacting numerous Operational Technology (OT), Internet of Things (IoT), Building Automation Systems, and Information Technology (IT) devices. The 33 vulnerabilities could cause denial of service, unauthorized information disclosure and several remote code execution errors. According to Forescout, at least 150 vendors may have implemented libraries affected by Amnesia:33. Of the 33 reported vulnerabilities, 3 were classified as critical and require immediate attention.