Networked Energy Services Products Unaffected by AMNESIA:33 TCP Vulnerability

NES maintains high state of vigilance to ensure that its products and solutions provide industry leading cyber-security

San Jose, CA, December 9th, 2020: On December 8th, 2020, Forescout1 disclosed 33 software security vulnerabilities affecting millions of embedded devices worldwide. This bundle of vulnerabilities is called AMNESIA:33. They were found in four open-source TCP/IP stacks; 4 of the vulnerabilities are considered critical. 

NES has immediately conducted a review of its products and solutions and can confirm that they are unaffected by AMNESIA:33 vulnerabilities. AMNESIA:33 applies to four specific implementations of the TCP/IP stack. NES products do not use these stacks.

NES can also confirm that the Open Smart Grid Protocol (OSGP), that it employs in its meters, does not utilize these TCP/IP stacks and so is unaffected.

NES takes all aspects of the security of its products very seriously. This includes the responsibility for brisk disclosure of any identified security vulnerabilities to customers and partners. Cyber-security is of growing concern in the utilities sector and especially in Smart Grids.

