SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#145825

SISCO OSI stack fails to properly handle malformed packets

Overview

A vulnerability exists in the SISCO OSI stack. If this vulnerability is successfully exploited, an attacker could cause a denial-of-service condition.

I. Description

The SISCO OSI stack is a component of the SISCO MMS-EASE, ICCP Toolkit for MMS-EASE, AX-S4 MMS and AX-S4 ICCP products. The SISCO OSI stack fails to properly handle malformed packets. A remote attacker may be able to trigger this vulnerability by sending a specially crafted series of packets to a vulnerable SISCO OSI stack installation.

Note that a valid connection is needed to trigger this vulnerability.

The SISCO OSI stack is used in a wide variety of control system applications. Users should check their applications to ensure they are using a non-vulnerable version of the SISCO OSI stack. Users are encouraged to contact their software vendors if they suspect they are vulnerable.

II. Impact

A remote attacker can cause the OSI stack to terminate abnormally resulting in a denial-of-service condition requiring an application using the SISCO OSI stack and the SISCO OSI stack itself to be restarted.

III. Solution

Upgrade or Patch accordingly

SISCO has corrected this problem in the latest version of the SISCO OSI stack. SISCO has also released patches to address this issue in older versions of the SISCO OSI stack for Windows.

Restrict Access

Restrict remote access to only trusted hosts by using firewalls or only connecting them to private networks.

Systems Affected

VendorStatusDate NotifiedDate Updated
SISCO - Systems Integration Specialists Company, Inc.Vulnerable12-Jan-2007

References


http://www.sisconet.com/home.htm
http://www.sisconet.com/contact.htm
http://secunia.com/advisories/23819/
http://www.securityfocus.com/bid/22095

Credit

Thanks to Matthew D. Franz for researching and reporting this vulnerability.

This document was written by Jeff Gennari.

Other Information

Date Public:2007-01-17
Date First Published:2007-01-17
Date Last Updated:2007-01-26
CERT Advisory: 
CVE-ID(s):CVE-2006-6489
NVD-ID(s):CVE-2006-6489
US-CERT Technical Alerts: 
Metric:0.50
Document Revision:39

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader