CVE-2025-23406
MEDIUMCente middleware TCP/IP Network Series - Info Disclosure
Title source: llmDescription
Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a specially crafted packet to cause the affected product crashed.
References (2)
Core 2
Core References
Various Sources
https://www.cente.jp/obstacle/5451/
Third Party Advisory
https://jvn.jp/en/vu/JVNVU92227620/
Scores
CVSS v3
5.3
EPSS
0.0011
EPSS Percentile
29.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (6)
DMG MORI Digital Co., LTD. and NXTech Co., Ltd./Cente IPv6
Ver.1.60 and earlier
DMG MORI Digital Co., LTD. and NXTech Co., Ltd./Cente IPv6 SNMPv2
Ver.2.30 and earlier
DMG MORI Digital Co., LTD. and NXTech Co., Ltd./Cente IPv6 SNMPv3
Ver.2.30 and earlier
DMG MORI Digital Co., LTD. and NXTech Co., Ltd./Cente TCP/IPv4
Ver.1.51 and earlier
DMG MORI Digital Co., LTD. and NXTech Co., Ltd./Cente TCP/IPv4 SNMPv2
Ver.2.30 and earlier
DMG MORI Digital Co., LTD. and NXTech Co., Ltd./Cente TCP/IPv4 SNMPv3
Ver.2.30 and earlier
Published
Feb 14, 2025
Tracked Since
Feb 18, 2026