GHSA-ppmm-3cm9-263hHighCVSS 7.5

MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body...

Published
September 4, 2026
Last Modified
September 4, 2026

🔗 CVE IDs covered (1)

📋 Description

MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.

🔗 References (7)