« Volver al listado

CVE-2024-28957

Estado: AnalizadaMedia (5.3)—

Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-28957",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-28957",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-07T15:53:21.774024Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.",
          "product": "Cente TCP/IPv4",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.41 and earlier"
            }
          ]
        },
        {
          "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.",
          "product": "Cente TCP/IPv4 SNMPv2",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.30 and earlier"
            }
          ]
        },
        {
          "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.",
          "product": "Cente TCP/IPv4 SNMPv3",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.30 and earlier"
            }
          ]
        },
        {
          "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.",
          "product": "Cente IPv6",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.51 and earlier"
            }
          ]
        },
        {
          "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.",
          "product": "Cente IPv6 SNMPv2",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.30 and earlier"
            }
          ]
        },
        {
          "vendor": "DMG MORI Digital Co., LTD. and NEXT Co., Ltd.",
          "product": "Cente IPv6 SNMPv3",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.30 and earlier"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:cente:ipv6:*:*:*:*:*:*:*:*"
          ],
          "vendor": "cente",
          "product": "ipv6",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "1.51"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:cente:ipv6_snmpv2:*:*:*:*:*:*:*:*"
          ],
          "vendor": "cente",
          "product": "ipv6_snmpv2",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2.30"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:cente:ipv6_snmpv3:*:*:*:*:*:*:*:*"
          ],
          "vendor": "cente",
          "product": "ipv6_snmpv3",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2.30"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:cente:ipv4snmpv2:*:*:*:*:*:*:*:*"
          ],
          "vendor": "cente",
          "product": "ipv4snmpv2",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2.30"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:cente:ipv4snmpv3:*:*:*:*:*:*:*:*"
          ],
          "vendor": "cente",
          "product": "ipv4snmpv3",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2.30"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:cente:ipv4:*:*:*:*:*:*:*:*"
          ],
          "vendor": "cente",
          "product": "ipv4",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "1.41"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-04-15T11:15:08.490",
  "references": [
    {
      "url": "https://jvn.jp/en/vu/JVNVU94016877/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.cente.jp/obstacle/4956/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.cente.jp/obstacle/4963/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/vu/JVNVU94016877/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cente.jp/obstacle/4956/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cente.jp/obstacle/4963/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-340"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device."
    },
    {
      "lang": "es",
      "value": "Existe un problema de generación de identificadores predecibles en la serie de redes TCP/IP del middleware Cente. Si se explota esta vulnerabilidad, un atacante remoto no autenticado puede interferir en las comunicaciones al predecir algunos ID de encabezado de paquete del dispositivo."
    }
  ],
  "lastModified": "2026-06-17T07:22:09.383",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nxtech:cente_ipv6:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D29307C-6D00-4A45-ACAB-23F7BFEC8EFF",
              "versionEndIncluding": "1.51"
            },
            {
              "criteria": "cpe:2.3:a:nxtech:cente_ipv6_snmpv2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7937B3BF-CFFD-47A5-A76A-692F4D5F4C95",
              "versionEndIncluding": "2.30"
            },
            {
              "criteria": "cpe:2.3:a:nxtech:cente_ipv6_snmpv3:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFB0C9DD-AEE3-4C4C-93BD-A717EE4C29E3",
              "versionEndIncluding": "2.30"
            },
            {
              "criteria": "cpe:2.3:a:nxtech:cente_tcp\\/ipv4:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C5EF4EE-53EF-41D7-A134-2A3E9A256E31",
              "versionEndIncluding": "1.41"
            },
            {
              "criteria": "cpe:2.3:a:nxtech:cente_tcp\\/ipv4_snmpv2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F9ED3FC-6880-4945-A40F-1C873273D5D0",
              "versionEndIncluding": "2.30"
            },
            {
              "criteria": "cpe:2.3:a:nxtech:cente_tcp\\/ipv4_snmpv3:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F523D92-2469-410A-B147-D6F122204DB4",
              "versionEndIncluding": "2.30"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}