CVE-2026-85429
nicheNode identity spoofing in MOOS-IvP uFldNodeComms via unvalidated message sources
The uFldNodeComms application in the MOOS-IvP autonomy suite, in all versions through 24.8.1, accepts the source node identity claimed inside a NODE_MESSAGE packet body without verifying it against the actual connection the message arrived on (CWE-345, insufficient verification of data authenticity). An attacker with network access to the MOOS comms channel can send crafted NODE_MESSAGE packets claiming to come from a different node. This lets the attacker impersonate other nodes and post arbitrary variable notifications into the shared MOOS variable space without validation, undermining trust in the multi-vehicle messaging flow; the CVSS 4.0 score of 8.7 reflects a high integrity-only impact with no confidentiality or availability loss. Anyone running MOOS-IvP up to and including 24.8.1 with uFldNodeComms in multi-vehicle or networked operations is affected. There are currently no reports of exploitation in the wild, no known public proof-of-concept, a low EPSS of 0.2%, and the issue is not in the CISA KEV catalog.
What to do: Upgrade MOOS-IvP to a release newer than 24.8.1 when a patched version becomes available, and monitor the project's repository or changelog for the fix. Until then, restrict network access to the MOOS comms ports used by uFldNodeComms to trusted vehicles and hosts, and treat node identities reported in message bodies as unverified rather than trusted for access decisions.
| MOOS-IvP uFldNodeComms | all versions through 24.8.1 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.
- Weakness
- CWE-345
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.