H-ISAC-TLP White Finished Intelligence Report: HC3 Analyst Note - NAME:WRECK April 16, 2021

On 12 April 2021, security researchers disclosed a series of medium, high and critical severity DNS vulnerabilities impacting the TCP/IP stacks present in potentially millions of enterprise and consumer devices, with organizations in the healthcare and government sectors impacted most. The flaws could enable threat actors to take affected devices offline or gain control over them. While some patches have been released and mitigations are available, many organizations may encounter hurdles applying the patches where centralized vulnerability management is not an option and many device owners may not even be aware that devices contain these vulnerable TCP/IP stacks. Mitigations for the HPH sector can be found at the end of the attached report here