Headline
CVE-2022-42982: BKG Professional NtripCaster
BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can be used for UDP amplification attacks. Normally, only authenticated streaming data will be provided over UDP and not the sourcetable.
BKG Professional NtripCaster (Datasheet)****Application and Specifications
The BKG Professional NtripCaster allows the dissemination of GNSS real-time data streams via internet. The software supports the Ntrip internet protocol in version 1 and 2. For more details on the Ntrip protocol, please see here.
The software has been developed within the framework of the EUREF-IP project. It is based on the ICECAST Internet Radio software written in C programming language under GNU General Public License (GPL). The caster is running on Linux systems and has been tested successfully on various distributions, such as Suse, Debian, Gentoo, and Red Hat. The software supports more than 100 NtripServers and more than 2000 listening NtripClients simultaneously. There are more than 100 operational installations worldwide. For technical details, see the manual.
Order and Delivery
The BKG Professional NtripCaster can be purchased at a price of 1000€. This includes delivery of the software including the source code in C programming language. Installation or operation support is not included. Software developments and bug fixes are provided at no additional costs.
Please fill in the order form below. Submit the form and you will receive an invoice by BKG. As soon as the BKG has received your payment the software will be delivered by e-mail including installation documentation, software documentation and source code.
Contact
Federal Agency for Cartography and Geodesy (BKG)
Section Satellite Navigation
Richard-Strauss-Allee 11, 60598 Frankfurt / Main
Germany
E-Mail: [email protected]
Disclaimer: BKG does not give any warranty regarding the function of the BKG Professional NtripCaster. Moreover, the BKG disclaims any liability nor responsibility to any person or entity with respect to any loss or damage caused, or alleged to be caused, directly or indirectly by the use of BKG Professional NtripCaster.