MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses. | |
| Title | MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping | |
| Weaknesses | CWE-345 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T22:38:27.110Z
Reserved: 2026-09-03T19:50:55.525Z
Link: CVE-2026-85434
No data.
Status : Received
Published: 2026-09-03T23:17:22.643
Modified: 2026-09-03T23:17:22.643
Link: CVE-2026-85434
No data.
OpenCVE Enrichment
Updated: 2026-09-04T00:00:09Z
Weaknesses