« Volver al listado

CVE-2025-23406

Estado: AplazadaMedia (5.3)—

Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a specially crafted packet to cause the affected product crashed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-23406",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-23406",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-14T15:37:06.223307Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "vultures@jpcert.or.jp",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "DMG MORI Digital Co., LTD. and NXTech Co., Ltd.",
          "product": "Cente TCP/IPv4",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.51 and earlier"
            }
          ]
        },
        {
          "vendor": "DMG MORI Digital Co., LTD. and NXTech Co., Ltd.",
          "product": "Cente TCP/IPv4 SNMPv2",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.30 and earlier"
            }
          ]
        },
        {
          "vendor": "DMG MORI Digital Co., LTD. and NXTech Co., Ltd.",
          "product": "Cente TCP/IPv4 SNMPv3",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.30 and earlier"
            }
          ]
        },
        {
          "vendor": "DMG MORI Digital Co., LTD. and NXTech Co., Ltd.",
          "product": "Cente IPv6",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.60 and earlier"
            }
          ]
        },
        {
          "vendor": "DMG MORI Digital Co., LTD. and NXTech Co., Ltd.",
          "product": "Cente IPv6 SNMPv2",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.30 and earlier"
            }
          ]
        },
        {
          "vendor": "DMG MORI Digital Co., LTD. and NXTech Co., Ltd.",
          "product": "Cente IPv6 SNMPv3",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.30 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-02-14T05:15:12.567",
  "references": [
    {
      "url": "https://jvn.jp/en/vu/JVNVU92227620/",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.cente.jp/obstacle/5451/",
      "source": "vultures@jpcert.or.jp"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vultures@jpcert.or.jp",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a specially crafted packet to cause the affected product crashed."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de lectura fuera de los límites causada por una verificación incorrecta de los valores de las opciones TCP MSS en el middleware TCP/IP Network Series de Cente, lo que puede llevar al procesamiento de un paquete especialmente manipulado para provocar el bloqueo del producto afectado."
    }
  ],
  "lastModified": "2026-06-17T08:54:06.497",
  "sourceIdentifier": "vultures@jpcert.or.jp"
}