Vulnerabilites related to nxtech - cente_ipv6
CVE-2024-28957 (GCVE-0-2024-28957)
Vulnerability from cvelistv5
Published
2024-04-15 10:48
Modified
2024-08-29 20:06
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Generation of Predictable Numbers or Identifiers
Summary
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device.
References
Impacted products
Vendor | Product | Version | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | DMG MORI Digital Co., LTD. and NEXT Co., Ltd. | Cente TCP/IPv4 |
Version: Ver.1.41 and earlier |
||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-02T01:03:51.396Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.cente.jp/obstacle/4963/" }, { "tags": [ "x_transferred" ], "url": "https://www.cente.jp/obstacle/4956/" }, { "tags": [ "x_transferred" ], "url": "https://jvn.jp/en/vu/JVNVU94016877/" } ], "title": "CVE Program Container" }, { "affected": [ { "cpes": [ "cpe:2.3:a:cente:ipv6:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv6", "vendor": "cente", "versions": [ { "lessThanOrEqual": "1.51", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:cente:ipv6_snmpv2:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv6_snmpv2", "vendor": "cente", "versions": [ { "lessThanOrEqual": "2.30", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:cente:ipv6_snmpv3:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv6_snmpv3", "vendor": "cente", "versions": [ { "lessThanOrEqual": "2.30", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:cente:ipv4snmpv2:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv4snmpv2", "vendor": "cente", "versions": [ { "lessThanOrEqual": "2.30", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:cente:ipv4snmpv3:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv4snmpv3", "vendor": "cente", "versions": [ { "lessThanOrEqual": "2.30", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:cente:ipv4:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv4", "vendor": "cente", "versions": [ { "lessThanOrEqual": "1.41", "status": "affected", "version": "0", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-28957", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2024-08-07T15:53:21.774024Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-340", "description": "CWE-340 Generation of Predictable Numbers or Identifiers", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-08-29T20:06:59.433Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "product": "Cente TCP/IPv4", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.1.41 and earlier" } ] }, { "product": "Cente TCP/IPv4 SNMPv2", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.2.30 and earlier" } ] }, { "product": "Cente TCP/IPv4 SNMPv3", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.2.30 and earlier" } ] }, { "product": "Cente IPv6", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.1.51 and earlier" } ] }, { "product": "Cente IPv6 SNMPv2", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.2.30 and earlier" } ] }, { "product": "Cente IPv6 SNMPv3", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.2.30 and earlier" } ] } ], "descriptions": [ { "lang": "en", "value": "Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device." } ], "problemTypes": [ { "descriptions": [ { "description": "Generation of Predictable Numbers or Identifiers", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2024-04-15T10:48:59.978Z", "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "shortName": "jpcert" }, "references": [ { "url": "https://www.cente.jp/obstacle/4963/" }, { "url": "https://www.cente.jp/obstacle/4956/" }, { "url": "https://jvn.jp/en/vu/JVNVU94016877/" } ] } }, "cveMetadata": { "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "assignerShortName": "jpcert", "cveId": "CVE-2024-28957", "datePublished": "2024-04-15T10:48:59.978Z", "dateReserved": "2024-03-19T01:42:41.530Z", "dateUpdated": "2024-08-29T20:06:59.433Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-28894 (GCVE-0-2024-28894)
Vulnerability from cvelistv5
Published
2024-04-15 10:47
Modified
2024-08-02 01:03
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Out-of-bounds read
Summary
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.
References
Impacted products
Vendor | Product | Version | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | DMG MORI Digital Co., LTD. and NEXT Co., Ltd. | Cente IPv6 |
Version: Ver.1.51 and earlier |
|||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:cente:ipv6:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv6", "vendor": "cente", "versions": [ { "lessThanOrEqual": "1.51", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:cente:ipv6_snmpv2:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv6_snmpv2", "vendor": "cente", "versions": [ { "lessThanOrEqual": "2.30", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:cente:ipv6_snmpv3:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv6_snmpv3", "vendor": "cente", "versions": [ { "lessThanOrEqual": "2.30", "status": "affected", "version": "0", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-28894", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2024-07-30T19:59:04.702338Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-07-30T20:03:08.902Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T01:03:50.255Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.cente.jp/obstacle/4960/" }, { "tags": [ "x_transferred" ], "url": "https://jvn.jp/en/vu/JVNVU94016877/" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Cente IPv6", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.1.51 and earlier" } ] }, { "product": "Cente IPv6 SNMPv2", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.2.30 and earlier" } ] }, { "product": "Cente IPv6 SNMPv3", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.2.30 and earlier" } ] } ], "descriptions": [ { "lang": "en", "value": "Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet." } ], "problemTypes": [ { "descriptions": [ { "description": "Out-of-bounds read", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2024-04-15T10:47:50.522Z", "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "shortName": "jpcert" }, "references": [ { "url": "https://www.cente.jp/obstacle/4960/" }, { "url": "https://jvn.jp/en/vu/JVNVU94016877/" } ] } }, "cveMetadata": { "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "assignerShortName": "jpcert", "cveId": "CVE-2024-28894", "datePublished": "2024-04-15T10:47:50.522Z", "dateReserved": "2024-03-19T01:42:40.699Z", "dateUpdated": "2024-08-02T01:03:50.255Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23911 (GCVE-0-2024-23911)
Vulnerability from cvelistv5
Published
2024-04-15 10:46
Modified
2024-08-01 23:13
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Out-of-bounds read
Summary
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.
References
Impacted products
Vendor | Product | Version | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | DMG MORI Digital Co., LTD. and NEXT Co., Ltd. | Cente IPv6 |
Version: Ver.1.51 and earlier |
|||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:cente:ipv6:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv6", "vendor": "cente", "versions": [ { "lessThanOrEqual": "1.51", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:cente:ipv6_snmpv2:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv6_snmpv2", "vendor": "cente", "versions": [ { "lessThanOrEqual": "2.30", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:cente:ipv6_snmpv3:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "ipv6_snmpv3", "vendor": "cente", "versions": [ { "lessThanOrEqual": "2.30", "status": "affected", "version": "0", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23911", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2024-06-17T20:27:05.820784Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-06-17T20:27:09.860Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T23:13:08.598Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.cente.jp/obstacle/4960/" }, { "tags": [ "x_transferred" ], "url": "https://jvn.jp/en/vu/JVNVU94016877/" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Cente IPv6", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.1.51 and earlier" } ] }, { "product": "Cente IPv6 SNMPv2", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.2.30 and earlier" } ] }, { "product": "Cente IPv6 SNMPv3", "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.", "versions": [ { "status": "affected", "version": "Ver.2.30 and earlier" } ] } ], "descriptions": [ { "lang": "en", "value": "Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet." } ], "problemTypes": [ { "descriptions": [ { "description": "Out-of-bounds read", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2024-04-15T10:46:29.583Z", "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "shortName": "jpcert" }, "references": [ { "url": "https://www.cente.jp/obstacle/4960/" }, { "url": "https://jvn.jp/en/vu/JVNVU94016877/" } ] } }, "cveMetadata": { "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "assignerShortName": "jpcert", "cveId": "CVE-2024-23911", "datePublished": "2024-04-15T10:46:29.583Z", "dateReserved": "2024-03-19T01:42:39.688Z", "dateUpdated": "2024-08-01T23:13:08.598Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
Vulnerability from fkie_nvd
Published
2024-04-15 11:15
Modified
2025-06-30 13:36
Severity ?
Summary
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device.
References
▶ | URL | Tags | |
---|---|---|---|
vultures@jpcert.or.jp | https://jvn.jp/en/vu/JVNVU94016877/ | Third Party Advisory | |
vultures@jpcert.or.jp | https://www.cente.jp/obstacle/4956/ | Vendor Advisory | |
vultures@jpcert.or.jp | https://www.cente.jp/obstacle/4963/ | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://jvn.jp/en/vu/JVNVU94016877/ | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.cente.jp/obstacle/4956/ | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.cente.jp/obstacle/4963/ | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
nxtech | cente_ipv6 | * | |
nxtech | cente_ipv6_snmpv2 | * | |
nxtech | cente_ipv6_snmpv3 | * | |
nxtech | cente_tcp\/ipv4 | * | |
nxtech | cente_tcp\/ipv4_snmpv2 | * | |
nxtech | cente_tcp\/ipv4_snmpv3 | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:nxtech:cente_ipv6:*:*:*:*:*:*:*:*", "matchCriteriaId": "5D29307C-6D00-4A45-ACAB-23F7BFEC8EFF", "versionEndIncluding": "1.51", "vulnerable": true }, { "criteria": "cpe:2.3:a:nxtech:cente_ipv6_snmpv2:*:*:*:*:*:*:*:*", "matchCriteriaId": "7937B3BF-CFFD-47A5-A76A-692F4D5F4C95", "versionEndIncluding": "2.30", "vulnerable": true }, { "criteria": "cpe:2.3:a:nxtech:cente_ipv6_snmpv3:*:*:*:*:*:*:*:*", "matchCriteriaId": "EFB0C9DD-AEE3-4C4C-93BD-A717EE4C29E3", "versionEndIncluding": "2.30", "vulnerable": true }, { "criteria": "cpe:2.3:a:nxtech:cente_tcp\\/ipv4:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C5EF4EE-53EF-41D7-A134-2A3E9A256E31", "versionEndIncluding": "1.41", "vulnerable": true }, { "criteria": "cpe:2.3:a:nxtech:cente_tcp\\/ipv4_snmpv2:*:*:*:*:*:*:*:*", "matchCriteriaId": "5F9ED3FC-6880-4945-A40F-1C873273D5D0", "versionEndIncluding": "2.30", "vulnerable": true }, { "criteria": "cpe:2.3:a:nxtech:cente_tcp\\/ipv4_snmpv3:*:*:*:*:*:*:*:*", "matchCriteriaId": "3F523D92-2469-410A-B147-D6F122204DB4", "versionEndIncluding": "2.30", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device." }, { "lang": "es", "value": "Existe un problema de generaci\u00f3n de identificadores predecibles en la serie de redes TCP/IP del middleware Cente. Si se explota esta vulnerabilidad, un atacante remoto no autenticado puede interferir en las comunicaciones al predecir algunos ID de encabezado de paquete del dispositivo." } ], "id": "CVE-2024-28957", "lastModified": "2025-06-30T13:36:46.470", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-04-15T11:15:08.490", "references": [ { "source": "vultures@jpcert.or.jp", "tags": [ "Third Party Advisory" ], "url": "https://jvn.jp/en/vu/JVNVU94016877/" }, { "source": "vultures@jpcert.or.jp", "tags": [ "Vendor Advisory" ], "url": "https://www.cente.jp/obstacle/4956/" }, { "source": "vultures@jpcert.or.jp", "tags": [ "Vendor Advisory" ], "url": "https://www.cente.jp/obstacle/4963/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://jvn.jp/en/vu/JVNVU94016877/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.cente.jp/obstacle/4956/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.cente.jp/obstacle/4963/" } ], "sourceIdentifier": "vultures@jpcert.or.jp", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-340" } ], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-04-15 11:15
Modified
2025-06-30 13:34
Severity ?
Summary
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.
References
▶ | URL | Tags | |
---|---|---|---|
vultures@jpcert.or.jp | https://jvn.jp/en/vu/JVNVU94016877/ | Third Party Advisory | |
vultures@jpcert.or.jp | https://www.cente.jp/obstacle/4960/ | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://jvn.jp/en/vu/JVNVU94016877/ | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.cente.jp/obstacle/4960/ | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
nxtech | cente_ipv6 | * | |
nxtech | cente_ipv6_snmpv2 | * | |
nxtech | cente_ipv6_snmpv3 | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:nxtech:cente_ipv6:*:*:*:*:*:*:*:*", "matchCriteriaId": "5D29307C-6D00-4A45-ACAB-23F7BFEC8EFF", "versionEndIncluding": "1.51", "vulnerable": true }, { "criteria": "cpe:2.3:a:nxtech:cente_ipv6_snmpv2:*:*:*:*:*:*:*:*", "matchCriteriaId": "7937B3BF-CFFD-47A5-A76A-692F4D5F4C95", "versionEndIncluding": "2.30", "vulnerable": true }, { "criteria": "cpe:2.3:a:nxtech:cente_ipv6_snmpv3:*:*:*:*:*:*:*:*", "matchCriteriaId": "EFB0C9DD-AEE3-4C4C-93BD-A717EE4C29E3", "versionEndIncluding": "2.30", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet." }, { "lang": "es", "value": "Existe una vulnerabilidad de lectura fuera de los l\u00edmites causada por una verificaci\u00f3n incorrecta de los valores de longitud de las opciones en los encabezados IPv6 en la serie de redes TCP/IP del middleware Cente, que puede permitir que un atacante no autenticado detenga las operaciones del dispositivo enviando un paquete especialmente manipulado." } ], "id": "CVE-2024-28894", "lastModified": "2025-06-30T13:34:04.667", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-04-15T11:15:08.440", "references": [ { "source": "vultures@jpcert.or.jp", "tags": [ "Third Party Advisory" ], "url": "https://jvn.jp/en/vu/JVNVU94016877/" }, { "source": "vultures@jpcert.or.jp", "tags": [ "Vendor Advisory" ], "url": "https://www.cente.jp/obstacle/4960/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://jvn.jp/en/vu/JVNVU94016877/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.cente.jp/obstacle/4960/" } ], "sourceIdentifier": "vultures@jpcert.or.jp", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-04-15 11:15
Modified
2025-06-30 13:32
Severity ?
Summary
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.
References
▶ | URL | Tags | |
---|---|---|---|
vultures@jpcert.or.jp | https://jvn.jp/en/vu/JVNVU94016877/ | Third Party Advisory | |
vultures@jpcert.or.jp | https://www.cente.jp/obstacle/4960/ | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://jvn.jp/en/vu/JVNVU94016877/ | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.cente.jp/obstacle/4960/ | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
nxtech | cente_ipv6 | * | |
nxtech | cente_ipv6_snmpv2 | * | |
nxtech | cente_ipv6_snmpv3 | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:nxtech:cente_ipv6:*:*:*:*:*:*:*:*", "matchCriteriaId": "5D29307C-6D00-4A45-ACAB-23F7BFEC8EFF", "versionEndIncluding": "1.51", "vulnerable": true }, { "criteria": "cpe:2.3:a:nxtech:cente_ipv6_snmpv2:*:*:*:*:*:*:*:*", "matchCriteriaId": "7937B3BF-CFFD-47A5-A76A-692F4D5F4C95", "versionEndIncluding": "2.30", "vulnerable": true }, { "criteria": "cpe:2.3:a:nxtech:cente_ipv6_snmpv3:*:*:*:*:*:*:*:*", "matchCriteriaId": "EFB0C9DD-AEE3-4C4C-93BD-A717EE4C29E3", "versionEndIncluding": "2.30", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet." }, { "lang": "es", "value": "Existe una vulnerabilidad de lectura fuera de los l\u00edmites causada por una verificaci\u00f3n incorrecta de los valores de longitud de las opciones en los paquetes IPv6 NDP en la serie de redes TCP/IP del middleware Cente, lo que puede permitir que un atacante no autenticado detenga las operaciones del dispositivo enviando un paquete especialmente manipulado." } ], "id": "CVE-2024-23911", "lastModified": "2025-06-30T13:32:36.317", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 3.6, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-04-15T11:15:08.227", "references": [ { "source": "vultures@jpcert.or.jp", "tags": [ "Third Party Advisory" ], "url": "https://jvn.jp/en/vu/JVNVU94016877/" }, { "source": "vultures@jpcert.or.jp", "tags": [ "Vendor Advisory" ], "url": "https://www.cente.jp/obstacle/4960/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://jvn.jp/en/vu/JVNVU94016877/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.cente.jp/obstacle/4960/" } ], "sourceIdentifier": "vultures@jpcert.or.jp", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }