ZeroHour

CVE-2026-85429

niche

Node identity spoofing in MOOS-IvP uFldNodeComms via unvalidated message sources

CVSS 4.0
8.7 high
EPSS
<1%p8
Published
()
Modified
AI analysis

The uFldNodeComms application in the MOOS-IvP autonomy suite, in all versions through 24.8.1, accepts the source node identity claimed inside a NODE_MESSAGE packet body without verifying it against the actual connection the message arrived on (CWE-345, insufficient verification of data authenticity). An attacker with network access to the MOOS comms channel can send crafted NODE_MESSAGE packets claiming to come from a different node. This lets the attacker impersonate other nodes and post arbitrary variable notifications into the shared MOOS variable space without validation, undermining trust in the multi-vehicle messaging flow; the CVSS 4.0 score of 8.7 reflects a high integrity-only impact with no confidentiality or availability loss. Anyone running MOOS-IvP up to and including 24.8.1 with uFldNodeComms in multi-vehicle or networked operations is affected. There are currently no reports of exploitation in the wild, no known public proof-of-concept, a low EPSS of 0.2%, and the issue is not in the CISA KEV catalog.

What to do: Upgrade MOOS-IvP to a release newer than 24.8.1 when a patched version becomes available, and monitor the project's repository or changelog for the fix. Until then, restrict network access to the MOOS comms ports used by uFldNodeComms to trusted vehicles and hosts, and treat node identities reported in message bodies as unverified rather than trusted for access decisions.

Affected
MOOS-IvP uFldNodeCommsall versions through 24.8.1 (inclusive)
Estimated exposure
nichelikely hundreds to low thousands of deployments worldwide (niche open-source marine robotics middleware; estimate, no public install counts) — MOOS-IvP is a niche open-source autonomy middleware used mainly in marine robotics research, education, and small multi-vehicle field operations, typically on isolated mission or lab networks rather than the public internet, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.

Weakness
CWE-345
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.