CVE-2024-23911
Estado: AnalizadaAlta (7.5)—
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.61%
- Percentil entre todas las CVEs puntuadas: 47
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-125
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-23911",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-23911",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-06-17T20:27:05.820784Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.",
"product": "Cente IPv6",
"versions": [
{
"status": "affected",
"version": "Ver.1.51 and earlier"
}
]
},
{
"vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.",
"product": "Cente IPv6 SNMPv2",
"versions": [
{
"status": "affected",
"version": "Ver.2.30 and earlier"
}
]
},
{
"vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.",
"product": "Cente IPv6 SNMPv3",
"versions": [
{
"status": "affected",
"version": "Ver.2.30 and earlier"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:cente:ipv6:*:*:*:*:*:*:*:*"
],
"vendor": "cente",
"product": "ipv6",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "1.51"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:cente:ipv6_snmpv2:*:*:*:*:*:*:*:*"
],
"vendor": "cente",
"product": "ipv6_snmpv2",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2.30"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:cente:ipv6_snmpv3:*:*:*:*:*:*:*:*"
],
"vendor": "cente",
"product": "ipv6_snmpv3",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2.30"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-04-15T11:15:08.227",
"references": [
{
"url": "https://jvn.jp/en/vu/JVNVU94016877/",
"tags": [
"Third Party Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.cente.jp/obstacle/4960/",
"tags": [
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://jvn.jp/en/vu/JVNVU94016877/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cente.jp/obstacle/4960/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de lectura fuera de los límites causada por una verificación incorrecta de los valores de longitud de las opciones en los paquetes IPv6 NDP en la serie de redes TCP/IP del middleware Cente, lo que puede permitir que un atacante no autenticado detenga las operaciones del dispositivo enviando un paquete especialmente manipulado."
}
],
"lastModified": "2026-06-17T07:13:52.447",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nxtech:cente_ipv6:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D29307C-6D00-4A45-ACAB-23F7BFEC8EFF",
"versionEndIncluding": "1.51"
},
{
"criteria": "cpe:2.3:a:nxtech:cente_ipv6_snmpv2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7937B3BF-CFFD-47A5-A76A-692F4D5F4C95",
"versionEndIncluding": "2.30"
},
{
"criteria": "cpe:2.3:a:nxtech:cente_ipv6_snmpv3:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EFB0C9DD-AEE3-4C4C-93BD-A717EE4C29E3",
"versionEndIncluding": "2.30"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vultures@jpcert.or.jp"
}