search menu icon-carat-right cmu-wordmark

CERT Coordination Center

LiveData ICCP Server heap buffer overflow vulnerability

Vulnerability Note VU#190617

Original Release Date: 2006-05-16 | Last Revised: 2008-09-22

Overview

LiveData ICCP Server contains a heap-based buffer overflow. This vulnerability may allow a remote attacker to crash the server.

Description

Inter-Control Center Communications Protocol (ICCP)

According to the LiveData ICCP Server white paper:

The Inter-Control Center Communications Protocol (ICCP) is being specified by utility organizations throughout the world to provide data exchange over wide area networks (WANs) between utility control centers, utilities, power pools, regional control centers, and Non-Utility Generators. ICCP is also an international standard: International Electrotechnical Commission (IEC) Telecontrol Application Service Element 2 (TASE.2).

ISO Transport Service over TCP (TPKT, RFC 1006)

RFC 1006 specifies how to run the OSI transport protocol on top of TCP/IP. In the layered protocol model, RFC 1006 is situated between the TCP and OSI transport layers.

LiveData ICCP Server and LiveData Server

LiveData ICCP Server records and transmits data to other control points in process control networks. According to the LiveData ICCP Server white paper:

The LiveData ICCP Server is based on LiveData's standard off-the-shelf software product, LiveData Server, which features a rich set of integration methods that can be easily applied to new and existing SCADA/EMS/DCS systems.
The Problem

The LiveData implementation of RFC 1006 is vulnerable to a heap-based buffer overflow. By sending a specially crafted packet to a vulnerable LiveData RFC 1006 implementation, a remote attacker may be able to trigger the overflow.

Impact

This vulnerability may allow a remote, unauthenticated attacker to crash a LiveData ICCP Server.

Solution

Upgrade
This issue is corrected in LiveData ICCP Server version 5.00.035.

Vendor Information

190617
 

View all 13 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Matt Franz of Digital Bond Inc. for reporting this vulnerability. Information used in this document came from LiveData.

This document was written by Jeff Gennari.

Other Information

CVE IDs: CVE-2006-0059
Severity Metric: 7.93
Date Public: 2006-05-16
Date First Published: 2006-05-16
Date Last Updated: 2008-09-22 22:14 UTC
Document Revision: 126

Sponsored by CISA.