moos-ivp vulnerability

MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.

Published 3 Sep 2026Updated 5 Sep 20265 sources
CVSS 8.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.