ICCP Invalid OSI-SSEL (SCADA)

info Nessus Network Monitor Plugin ID 6255

Synopsis

The remote ICCP server has just sent a 'Session Refuse PDU' message in response to an invalid OSI Layer Selector (SSEL) value.

Description

The remote ICCP server has just sent a 'Session Refuse PDU' message in response to an invalid OSI Layer Selector (SSEL) value. As SSEL values are typically only 2 to 4 bytes long, this could indicate that a client is 'brute-forcing' a valid SSEL value. This sort of attack can also impact Availability to the server.

Solution

N/A

Plugin Details

Severity: Info

ID: 6255

Family: SCADA

Published: 1/6/2012

Updated: 4/29/2016