CVE-2024-28957

Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nxtech:cente_ipv6:*:*:*:*:*:*:*:*
cpe:2.3:a:nxtech:cente_ipv6_snmpv2:*:*:*:*:*:*:*:*
cpe:2.3:a:nxtech:cente_ipv6_snmpv3:*:*:*:*:*:*:*:*
cpe:2.3:a:nxtech:cente_tcp\/ipv4:*:*:*:*:*:*:*:*
cpe:2.3:a:nxtech:cente_tcp\/ipv4_snmpv2:*:*:*:*:*:*:*:*
cpe:2.3:a:nxtech:cente_tcp\/ipv4_snmpv3:*:*:*:*:*:*:*:*

History

30 Jun 2025, 13:36

Type Values Removed Values Added
CPE cpe:2.3:a:nxtech:cente_ipv6:*:*:*:*:*:*:*:*
cpe:2.3:a:nxtech:cente_tcp\/ipv4:*:*:*:*:*:*:*:*
cpe:2.3:a:nxtech:cente_tcp\/ipv4_snmpv3:*:*:*:*:*:*:*:*
cpe:2.3:a:nxtech:cente_ipv6_snmpv3:*:*:*:*:*:*:*:*
cpe:2.3:a:nxtech:cente_ipv6_snmpv2:*:*:*:*:*:*:*:*
cpe:2.3:a:nxtech:cente_tcp\/ipv4_snmpv2:*:*:*:*:*:*:*:*
First Time Nxtech cente Tcp\/ipv4 Snmpv3
Nxtech cente Ipv6 Snmpv3
Nxtech
Nxtech cente Tcp\/ipv4
Nxtech cente Ipv6 Snmpv2
Nxtech cente Ipv6
Nxtech cente Tcp\/ipv4 Snmpv2
References () https://jvn.jp/en/vu/JVNVU94016877/ - () https://jvn.jp/en/vu/JVNVU94016877/ - Third Party Advisory
References () https://www.cente.jp/obstacle/4956/ - () https://www.cente.jp/obstacle/4956/ - Vendor Advisory
References () https://www.cente.jp/obstacle/4963/ - () https://www.cente.jp/obstacle/4963/ - Vendor Advisory

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://jvn.jp/en/vu/JVNVU94016877/ - () https://jvn.jp/en/vu/JVNVU94016877/ -
References () https://www.cente.jp/obstacle/4956/ - () https://www.cente.jp/obstacle/4956/ -
References () https://www.cente.jp/obstacle/4963/ - () https://www.cente.jp/obstacle/4963/ -

29 Aug 2024, 20:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-340
Summary
  • (es) Existe un problema de generación de identificadores predecibles en la serie de redes TCP/IP del middleware Cente. Si se explota esta vulnerabilidad, un atacante remoto no autenticado puede interferir en las comunicaciones al predecir algunos ID de encabezado de paquete del dispositivo.

15 Apr 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-15 11:15

Updated : 2025-06-30 13:36


NVD link : CVE-2024-28957

Mitre link : CVE-2024-28957

CVE.ORG link : CVE-2024-28957


JSON object : View

Products Affected

nxtech

  • cente_tcp\/ipv4_snmpv2
  • cente_ipv6_snmpv3
  • cente_tcp\/ipv4_snmpv3
  • cente_tcp\/ipv4
  • cente_ipv6
  • cente_ipv6_snmpv2
CWE
CWE-340

Generation of Predictable Numbers or Identifiers