Distributed Network Protocol v3 'Cold Restart' Alert (SCADA) (deprecated)

medium Nessus Network Monitor Plugin ID 6248

Synopsis

PVS has just detected a client sending the server a code '0D' message.

Description

SCADA Alert - Distributed Network Protocol v3 'Cold Restart' alert. The remote host is running the Distributed Network Protocol version 3. This protocol is common on SCADA networks. NNM has just detected a client sending the server a code '0D' message. This message instructs the remote server to do a cold restart. That is, the server will be unavailable for some time as it restarts and runs all power-up tests.

Solution

If the PLC server supports it, disable 'Cold Restarts' except from trusted systems. Otherwise, ensure that SCADA network is only accessible by trusted hosts.

Plugin Details

Severity: Medium

ID: 6248

Family: SCADA

Published: 1/6/2012

Updated: 1/16/2019