CVE-2025-23406 Details
Description
Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a specially crafted packet to cause the affected product crashed.
An out-of-bounds read vulnerability has been identified in Cente middleware TCP/IP Network Series, developed by DMG MORI Digital Co., LTD. and provided by NXTech Co., Ltd. This vulnerability arises from improper handling of TCP Maximum Segment Size (MSS) option values, which can lead to a crash when the affected product processes a specially crafted packet. The vulnerability is present in several products and versions within the Cente middleware TCP/IP Network Series.
Users are advised to update the middleware to the latest version. For guidance on the update process, contact Cente support.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 14, 2025CISA-ADP
Assessed Feb 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU92227620/ | [email protected] | AdvisoryRemedy |
| https://www.cente.jp/obstacle/5451/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DMG MORI Digital Co., LTD. Cente TCP/IPv4 | <= 1.51 |
CPE
Remediation
| |
| DMG MORI Digital Co., LTD. Cente TCP/IPv4 SNMPv2 | <= 2.30 |
CPE
Remediation
| |
| DMG MORI Digital Co., LTD. Cente TCP/IPv4 SNMPv3 | <= 2.30 |
CPE
Remediation
| |
| DMG MORI Digital Co., LTD. Cente IPv6 | <= 1.60 |
CPE
Remediation
| |
| DMG MORI Digital Co., LTD. Cente IPv6 SNMPv2 | <= 2.30 |
CPE
Remediation
| |
| DMG MORI Digital Co., LTD. Cente IPv6 SNMPv3 | <= 2.30 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 14, 2025 | New CVE Received | [email protected] |
Volerion