We detect you are using an unsupported browser. For the best experience, please visit the site using Chrome, Firefox, Safari, or Edge. X
Maximize Your Experience: Reap the Personalized Advantages by Completing Your Profile to Its Fullest. Update Here
Stay in the loop with the latest from Microchip. Update your profile while you are at it. Update Here
Complete your profile to access more resources. Update Here

Amnesia:33 TCP/IP Vulnerabilities

Overview


Amnesia:33 refers to a set of 33 vulnerabilities affecting embedded Transmission Control Protocol and Internet Protocol (TCP/IP) stacks that may allow denial of service or remote code execution under certain conditions. Impact depends on the specific TCP/IP stack implementation used by the device.

Our hardware may be affected where vulnerable third-party or integrated TCP/IP stacks are used. Exploitability depends on network exposure, device configuration and the specific TCP/IP stack implementation.

Vulnerabilities Covered


This page addresses the following Amnesia:33‑related vulnerabilities identified by Common Vulnerabilities and Exposures (CVEs):

  • CVE-2020-13987: Out-of-bounds memory read possible due to TCP and User Data Protocol (UDP) checksum calculation in Internet Protocol version 4 (IPv4)

  • CVE-2020-17437: Memory corruption possible due to TCP packet processing

  • CVE-2020-17439: Domain Name System (DNS) cache poisoning possible due to DNS response processing 

  • CVE-2020-17440: Memory corruption possible due to DNS domain name decoding

  • CVE-2020-17441: DNS-related vulnerability due to improper handling of DNS responses

  • CVE-2020-17470: Improper input validation leading to potential memory corruption

  • CVE-2020-24334: Memory corruption possible due to DNS response processing 

Note: Not all Amnesia:33 vulnerabilities apply to every product or configuration. Of the 33 disclosed vulnerabilities, only those applicable to our software or firmware are listed above.

Affected Products and Resolution


Last Updated: June 30, 2026

Software/FirmwareAssociated HardwareCVEResolution/Mitigation
ATWINC1500 FirmwareATSAMW25H18
ATWINC1500, ATWIN1500-IC
ATWINC1510, ATWINC1510-IC

CVE-2020-13987

CVE-2020-17437

CVE-2020-17439

CVE-2020-17440

CVE-2020-24334

Update to version 19.7.3 or later
ATWINC3400 FirmwareATWINC3400, ATWINC3400-IC

CVE-2020-13987

CVE-2020-17437

CVE-2020-17439

CVE-2020-17440

CVE-2020-24334

Update to version 1.4.1 or later
MPLAB® Code Configurator (MCC) Melody TCP/IP Lite LibraryWFI32E04UC, WFI32E04UE, WFI32E03PC, WFI32E03UC, WFI32E03PE, WFI32E03UE, WFI32E02UC, WFI32E02UE, WFI32E01PC, WFI32E01UC, WFI32E01PE, WFI32E01UE, PIC32MZ2051W104132, PIC32MZ1025W104132CVE-2020-17470Update to version 4.0.0 or later
MPLAB Harmony v3 Framework Net RepositoryWFI32E04UC, WFI32E04UE, WFI32E03PC, WFI32E03UC, WFI32E03PE, WFI32E03UE, WFI32E02UC, WFI32E02UE, WFI32E01PC, WFI32E01UC, WFI32E01PE, WFI32E01UE, PIC32MZ2051W104132, PIC32MZ1025W104132

CVE-2020-17439

CVE-2020-17441

Update to version 3.7.0 or later
Microchip Libraries for Applications (MLA) FrameworkATSAMW25H18
ATWINC1500, ATWIN1500-IC
ATWINC1510, ATWINC1510-IC
ATWINC3400, ATWINC3400-IC

CVE-2020-13987

CVE-2020-17437

CVE-2020-17439

CVE-2020-17440

CVE-2020-24334

Update ATSAMW25H18 AND ATWINC1500/10 to firmware version 19.7.3 or later

Update ATWINC3400 firmware to version 1.4.1 or later

Legacy 6LowPAN Likely, uses Contiki OSNo resolution available; product is End of Life (EOL)

Products Not Listed


Only products listed in the Affected Products and Resolution section of this advisory are known to be affected by these vulnerabilities.

Software Framework Impact and Mitigations


Amnesia:33 vulnerabilities affect TCP/IP stack implementations rather than wireless implementations. 

  • For Microchip products with TCP/IP stacks integrated into firmware, mitigation is provided through firmware updates
  • For systems using software frameworks, such as MPLAB® Harmony, or host-based environments, such as Linux®, vulnerability status depends on the TCP/IP stack used

Customers should ensure that all relevant software components, including Microchip frameworks, third-party libraries and open-source TCP/IP stacks, are updated to versions that address these vulnerabilities. 

Reference Documentation


Reference documentation includes the following third-party research material:

Live Chat

Need Help?

Privacy Policy