GHSA-cgqh-8w72-p7rfCriticalCVSS 9.1

MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating...

Published
September 4, 2026
Last Modified
September 4, 2026

🔗 CVE IDs covered (1)

📋 Description

MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.

🔗 References (7)