The way I see it --correct me if I am wrong-- is that Ripple has zero defenses against an attacker controlling many public IPv4 or IPv6 addresses and broadcasting his transactions to effectively control what the consensus is.
IOW, attacker-controlled Ripple nodes can outnumber legitimate Ripple nodes, therefore legit Ripple nodes are forced to accept transactions broadcasted by attacker-controlled nodes.