MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moos-ivp
Moos-ivp moos-ivp |
|
| Vendors & Products |
Moos-ivp
Moos-ivp moos-ivp |
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation. | |
| Title | MOOS-IvP through 24.8.1 uFldNodeComms Node Message Source Spoofing | |
| Weaknesses | CWE-345 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T22:38:23.780Z
Reserved: 2026-09-03T19:50:53.842Z
Link: CVE-2026-85429
No data.
Status : Received
Published: 2026-09-03T23:17:21.910
Modified: 2026-09-03T23:17:21.910
Link: CVE-2026-85429
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:21:39Z
Weaknesses